Symantec Norton Antivirus vulnerabilities
56 known vulnerabilities affecting symantec/norton_antivirus.
Total CVEs
56
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM27LOW4
Vulnerabilities
Page 2 of 3
CVE-2007-1476LOWCVSS 1.9PoCv3.0v9.0+31 more2007-03-16
CVE-2007-1476 [LOW] CVE-2007-1476: The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier,
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access
nvd
CVE-2006-6490CRITICALCVSS 10.0v20062007-02-22
CVE-2006-6490 [CRITICAL] CVE-2006-6490: Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgct
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
nvd
CVE-2006-3455MEDIUMCVSS 4.3v8.1v8.1.0.825a+20 more2006-10-23
CVE-2006-3455 [MEDIUM] CVE-2006-3455: The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.
nvd
CVE-2006-4855MEDIUMCVSS 4.9PoCv2.1v8.0+45 more2006-09-19
CVE-2006-4855 [MEDIUM] CWE-399 CVE-2006-4855: The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions o
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows loc
nvd
CVE-2006-3454HIGHCVSS 7.2v8.1v9.0+3 more2006-09-14
CVE-2006-3454 [HIGH] CVE-2006-3454: Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and C
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
nvd
CVE-2006-4802MEDIUMCVSS 4.6v8.1v8.1.1.319+9 more2006-09-14
CVE-2006-4802 [MEDIUM] CVE-2006-4802: Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edit
Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than CVE-2006-3454, a "second format string vulnerability" as found by the v
nvd
CVE-2006-2630CRITICALCVSS 10.0PoCv10.0v10.0.2.2010+4 more2006-05-27
CVE-2006-2630 [CRITICAL] CVE-2006-2630: Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attacke
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
nvd
CVE-2006-1836MEDIUMCVSS 6.8v9.0.0v9.0.1+6 more2006-04-19
CVE-2006-1836 [MEDIUM] CVE-2006-1836: Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
nvd
CVE-2005-3270HIGHCVSS 7.2v9.0.32005-10-21
CVE-2005-3270 [HIGH] CVE-2005-3270: Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows lo
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
nvd
CVE-2005-2759HIGHCVSS 7.2v9.0.32005-10-20
CVE-2005-2759 [HIGH] CVE-2005-2759: ** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh run
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the DiskMountNotify issue, and CVE-2005-2759 for the Li
nvd
CVE-2005-2766LOWCVSS 2.1v9.0.1.1.1000v9.0.42005-09-02
CVE-2005-2766 [LOW] CVE-2005-2766: Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtainin
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.
nvd
CVE-2005-2017CRITICALCVSS 10.0v9.0.1.10002005-08-30
CVE-2005-2017 [CRITICAL] CVE-2005-2017: Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for virus
Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.
nvd
CVE-2005-0922MEDIUMCVSS 5.0v2.1v20052005-05-02
CVE-2005-0922 [MEDIUM] CVE-2005-0922: Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.
nvd
CVE-2005-1346LOWCVSS 2.6v2005_11.0.02005-05-02
CVE-2005-1346 [LOW] CVE-2005-1346: Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Secur
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid de
nvd
CVE-2005-0923LOWCVSS 2.1v2.1v20052005-05-02
CVE-2005-0923 [LOW] CVE-2005-0923: The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as als
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.
nvd
CVE-2005-0249HIGHCVSS 7.5v2.18_build_83v8.1.1.319+12 more2005-02-08
CVE-2005-0249 [HIGH] CVE-2005-0249: Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attack
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
nvd
CVE-2004-2147MEDIUMCVSS 5.0v2.1v2001+14 more2004-12-31
CVE-2004-2147 [MEDIUM] CVE-2004-2147: Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denia
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
nvd
CVE-2004-0920MEDIUMCVSS 5.0≤ 2.12004-11-03
CVE-2004-0920 [MEDIUM] CVE-2004-0920: Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoi
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
nvd
CVE-2004-0487CRITICALCVSS 10.0v2.12004-08-18
CVE-2004-0487 [CRITICAL] CVE-2004-0487: A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denia
A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.
nvd
CVE-2004-0683MEDIUMCVSS 5.0PoCv2002v20032004-08-06
CVE-2004-0683 [MEDIUM] CVE-2004-0683: Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU co
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.
nvd