CVE-2007-0447
- EPSS 10.84%
- Veröffentlicht 05.10.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
CVE-2007-3699
- EPSS 2.38%
- Veröffentlicht 05.10.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
CVE-2007-0563
- EPSS 1.62%
- Veröffentlicht 30.01.2007 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produ...
- EPSS 0.53%
- Veröffentlicht 30.01.2007 16:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.
CVE-2005-1346
- EPSS 0.71%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4...
CVE-2005-0249
- EPSS 10.6%
- Veröffentlicht 08.02.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
CVE-2004-2755
- EPSS 1.09%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page...