CVE-2006-5404
- EPSS 0.71%
- Veröffentlicht 19.10.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via un...
CVE-2006-5403
- EPSS 23.99%
- Veröffentlicht 19.10.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash)...
CVE-2006-4855
- EPSS 0.27%
- Veröffentlicht 19.09.2006 18:07:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corpora...
CVE-2006-4802
- EPSS 0.08%
- Veröffentlicht 14.09.2006 22:07:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notific...
CVE-2006-3454
- EPSS 0.09%
- Veröffentlicht 14.09.2006 00:07:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification...
- EPSS 78.94%
- Veröffentlicht 27.05.2006 21:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
CVE-2006-1836
- EPSS 0.06%
- Veröffentlicht 19.04.2006 16:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
CVE-2005-3270
- EPSS 0.27%
- Veröffentlicht 21.10.2005 01:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
CVE-2005-2759
- EPSS 0.06%
- Veröffentlicht 20.10.2005 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assi...
CVE-2005-2766
- EPSS 0.08%
- Veröffentlicht 02.09.2005 10:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obta...