CVE-2022-25630
- EPSS 2.08%
- Veröffentlicht 09.12.2022 18:15:18
- Zuletzt bearbeitet 23.04.2025 15:15:47
An authenticated user can embed malicious content with XSS into the admin group policy page.
CVE-2022-25629
- EPSS 0.88%
- Veröffentlicht 09.12.2022 18:15:18
- Zuletzt bearbeitet 23.04.2025 15:15:47
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
CVE-2012-6277
- EPSS 3.25%
- Veröffentlicht 21.02.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:45:58
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data...
CVE-2019-18379
- EPSS 0.93%
- Veröffentlicht 11.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:10
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access...
CVE-2019-18378
- EPSS 0.32%
- Veröffentlicht 11.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:09
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vul...
CVE-2019-18377
- EPSS 1.05%
- Veröffentlicht 11.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:09
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are nor...
CVE-2019-9699
- EPSS 0.13%
- Veröffentlicht 24.10.2019 16:15:21
- Zuletzt bearbeitet 21.11.2024 04:52:07
Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.
CVE-2018-12243
- EPSS 0.23%
- Veröffentlicht 19.09.2018 15:29:19
- Zuletzt bearbeitet 21.11.2024 03:44:50
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. Th...
CVE-2018-12242
- EPSS 6.45%
- Veröffentlicht 19.09.2018 15:29:19
- Zuletzt bearbeitet 21.11.2024 03:44:50
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the s...
CVE-2017-15532
- EPSS 0.66%
- Veröffentlicht 20.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating var...