Show filters
598 Total Results
Displaying 1-10 of 598
Sort by:
Attacker Value
Unknown

CVE-2017-6327

Disclosure Date: August 11, 2017 (last updated July 25, 2024)
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.
Attacker Value
Unknown

CVE-2012-0297 Symantec Web Gateway Vulnerability

Disclosure Date: May 21, 2012 (last updated October 04, 2023)
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
0
Attacker Value
Unknown

Symantec Web Gateway upload_file Remote Code Execution Vulnerability

Disclosure Date: May 21, 2012 (last updated October 04, 2023)
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4422

Disclosure Date: August 18, 2007 (last updated October 04, 2023)
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
1
Attacker Value
Unknown

CVE-2023-23958

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
Attacker Value
Unknown

CVE-2023-23957

Disclosure Date: September 19, 2023 (last updated October 08, 2023)
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
Attacker Value
Unknown

CVE-2022-25630

Disclosure Date: December 09, 2022 (last updated October 08, 2023)
An authenticated user can embed malicious content with XSS into the admin group policy page.
Attacker Value
Unknown

CVE-2022-25629

Disclosure Date: December 09, 2022 (last updated October 08, 2023)
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
Attacker Value
Unknown

CVE-2022-37015

Disclosure Date: November 08, 2022 (last updated December 22, 2024)
Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Attacker Value
Unknown

CVE-2022-25623

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations.