Vulnerabilidades em Symantec Corporation

71 resultados
Análise Vexday

O histórico de vulnerabilidades da Symantec Corporation reúne 71 CVEs catalogadas, com taxa de exploração ativa que supera em 3,1 vezes a média geral do catálogo CISA KEV — sinal relevante considerando o volume relativamente modesto de entradas. A CVE em exploração confirmada atualmente é a CVE-2017-6327, com escore EPSS de 0,3534, indicando probabilidade não trivial de tentativas de exploração em ambientes reais. Chama atenção ainda que 7 CVEs possuem prova de conceito pública disponível, o que reduz a barreira técnica para agentes maliciosos, e que o maior EPSS observado no portfólio atinge 0,7276 — valor elevado que merece priorização imediata de análise. O tipo de falha mais recorrente é CWE-77 (injeção de comandos), padrão que costuma habilitar execução arbitrária de código e deve orientar revisões de configuração e controles de entrada em produtos legados da fabricante.

CVE-2018-12244SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula EPSS 1.7%CVE-2017-6324The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentiallyEPSS 1.7%CVE-2017-6331Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that EPSS 1.7%CVE-2016-9094Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logsEPSS 1.6%CVE-2017-18268Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has cEPSS 1.6%CVE-2018-5237Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a tEPSS 1.6%CVE-2018-5243The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploiEPSS 1.6%CVE-2018-12245Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that canEPSS 1.4%CVE-2016-10259Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerabilEPSS 1.4%CVE-2017-13678Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator EPSS 1.4%CVE-2018-12241The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remEPSS 1.3%CVE-2018-12246Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker EPSS 1.3%CVE-2018-18362Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a tEPSS 1.3%CVE-2017-6330Symantec Encryption Desktop before SED 10.4.1MP2 can allow remote attackers to cause a denial of service (resource consumption) via crafted EPSS 1.1%CVE-2018-12240The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type EPSS 1.1%CVE-2018-18364Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which is a type of issue EPSS 1.1%CVE-2018-5236Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issuEPSS 1.0%CVE-2018-18370The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browEPSS 0.9%CVE-2017-15532Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types oEPSS 0.9%CVE-2019-12753An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authenticated administrator usEPSS 0.9%