Symantec Endpoint Protection vulnerabilities

71 known vulnerabilities affecting symantec/endpoint_protection.

Total CVEs
71
CISA KEV
0
Public exploits
14
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH30MEDIUM32LOW2

Vulnerabilities

Page 3 of 4
CVE-2014-9229MEDIUMCVSS 6.5≤ 12.1.52015-09-20
CVE-2014-9229 [MEDIUM] CWE-89 CVE-2014-9229: Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role.
nvd
CVE-2014-3434MEDIUMCVSS 6.9PoCv11.0v12.0+1 more2014-08-06
CVE-2014-3434 [MEDIUM] CWE-119 CVE-2014-3434: Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x be Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.
nvd
CVE-2013-5011HIGHCVSS 7.2≤ 11.0.7.3v11.0+11 more2014-01-10
CVE-2013-5011 [HIGH] CWE-22 CVE-2013-5011: Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory.
nvd
CVE-2013-5009HIGHCVSS 7.4≤ 11.0.7.3v11.0+11 more2014-01-10
CVE-2013-5009 [HIGH] CWE-287 CVE-2013-5009: The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12 The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin account.
nvd
CVE-2013-5010MEDIUMCVSS 4.6≤ 11.0.7.3v11.0+11 more2014-01-10
CVE-2013-5010 [MEDIUM] CWE-264 CVE-2013-5010: The Application/Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 1 The Application/Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly handle custom polices, which allows local users to bypass intended policy restrictions and access files or directories
nvd
CVE-2012-4348HIGHCVSS 7.2v11.0v11.0.1+14 more2012-12-18
CVE-2012-4348 [HIGH] CWE-20 CVE-2012-4348: The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2 The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4953CRITICALCVSS 9.3v11.0v12.02012-11-14
CVE-2012-4953 [CRITICAL] CWE-119 CVE-2012-4953: The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service
nvd
CVE-2012-1821MEDIUMCVSS 5.0v11.0.6000v11.0.6100+5 more2012-05-24
CVE-2012-1821 [MEDIUM] CVE-2012-1821: The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network traffic.
nvd
CVE-2012-0295CRITICALCVSS 9.3v12.1v12.1.671+1 more2012-05-23
CVE-2012-0295 [CRITICAL] CVE-2012-0295: The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
nvd
CVE-2012-0289HIGHCVSS 7.2PoCv11.0.6000v11.0.6100+5 more2012-05-23
CVE-2012-0289 [HIGH] CWE-119 CVE-2012-0289: Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Netwo Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.
nvd
CVE-2012-0294MEDIUMCVSS 5.8v12.1v12.1.671+1 more2012-05-23
CVE-2012-0294 [MEDIUM] CWE-22 CVE-2012-0294: Directory traversal vulnerability in the Manager service in the management console in Symantec Endpo Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors.
nvd
CVE-2012-1443MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1443 [MEDIUM] CWE-264 CVE-2012-1443: The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 1 The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.
nvd
CVE-2012-1425MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1425 [MEDIUM] CWE-264 CVE-2012-1425: The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat Qui The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gate
nvd
CVE-2012-1461MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1461 [MEDIUM] CWE-264 CVE-2012-1461: The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Ems The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Sc
nvd
CVE-2012-1446MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1446 [MEDIUM] CWE-264 CVE-2012-1446: The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400 The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy
nvd
CVE-2012-1459MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1459 [MEDIUM] CWE-264 CVE-2012-1459: The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy La The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Ant
nvd
CVE-2012-1457MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1457 [MEDIUM] CWE-264 CVE-2012-1457: The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.13 The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Viru
nvd
CVE-2012-1462MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1462 [MEDIUM] CWE-264 CVE-2012-1462: The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, S
nvd
CVE-2012-1421MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1421 [MEDIUM] CWE-264 CVE-2012-1421: The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivi The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if addition
nvd
CVE-2012-1456MEDIUMCVSS 4.3v11.02012-03-21
CVE-2012-1456 [MEDIUM] CWE-264 CVE-2012-1456: The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Anti The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus
nvd