Symantec Message Gateway vulnerabilities
10 known vulnerabilities affecting symantec/message_gateway.
Total CVEs
10
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH8
Vulnerabilities
Page 1 of 1
CVE-2019-12751CRITICALCVSS 9.8fixed in 10.7.12019-07-11
CVE-2019-12751 [CRITICAL] CVE-2019-12751: Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerabil
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
nvd
CVE-2017-6327HIGHCVSS 8.8KEVPoCfixed in 10.6.3-2672017-08-11
CVE-2017-6327 [HIGH] CWE-77 CVE-2017-6327: The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, wh
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privil
nvd
CVE-2017-6328HIGHCVSS 8.8PoC≤ 10.6.3-22017-08-11
CVE-2017-6328 [HIGH] CWE-352 CVE-2017-6328: The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forger
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust t
nvd
CVE-2016-3645CRITICALCVSS 9.8PoC≤ 10.6.1-32016-06-30
CVE-2016-3645 [CRITICAL] CWE-189 CVE-2016-3645: Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linu
nvd
CVE-2016-3646HIGHCVSS 8.4PoC≤ 10.6.1-32016-06-30
CVE-2016-3646 [HIGH] CWE-20 CVE-2016-3646: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-2207HIGHCVSS 8.4PoC≤ 10.6.1-32016-06-30
CVE-2016-2207 [HIGH] CWE-20 CVE-2016-2207: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-3644HIGHCVSS 8.4PoC≤ 10.6.1-32016-06-30
CVE-2016-3644 [HIGH] CWE-20 CVE-2016-3644: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-2211HIGHCVSS 7.8≤ 10.6.1-32016-06-30
CVE-2016-2211 [HIGH] CWE-119 CVE-2016-2211: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection En
nvd
CVE-2016-2210HIGHCVSS 7.3PoC≤ 10.6.1-32016-06-30
CVE-2016-2210 [HIGH] CWE-119 CVE-2016-2210: Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protec
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12
nvd
CVE-2016-2209HIGHCVSS 7.3PoC≤ 10.6.1-32016-06-30
CVE-2016-2209 [HIGH] CWE-119 CVE-2016-2209: Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protect
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.
nvd