CVE-2015-1490
- EPSS 2.35%
- Published 01.08.2015 01:59:07
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via a relative pathname in a client installation package.
CVE-2015-1489
- EPSS 60.77%
- Published 01.08.2015 01:59:06
- Last modified 12.04.2025 10:46:40
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
- EPSS 0.49%
- Published 01.08.2015 01:59:05
- Last modified 12.04.2025 10:46:40
An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors.
CVE-2015-1487
- EPSS 51.2%
- Published 01.08.2015 01:59:04
- Last modified 12.04.2025 10:46:40
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.
CVE-2015-1486
- EPSS 78.5%
- Published 01.08.2015 01:59:03
- Last modified 12.04.2025 10:46:40
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
CVE-2014-3439
- EPSS 12.38%
- Published 07.11.2014 11:55:03
- Last modified 12.04.2025 10:46:40
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-3438
- EPSS 16.18%
- Published 07.11.2014 11:55:03
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-3437
- EPSS 22.28%
- Published 07.11.2014 11:55:03
- Last modified 12.04.2025 10:46:40
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with ...
CVE-2013-5015
- EPSS 74.05%
- Published 14.02.2014 13:10:30
- Last modified 11.04.2025 00:51:21
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows r...
CVE-2013-5014
- EPSS 86.2%
- Published 14.02.2014 13:10:27
- Last modified 11.04.2025 00:51:21
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitra...