Symantec Norton Internet Security vulnerabilities

33 known vulnerabilities affecting symantec/norton_internet_security.

Total CVEs
33
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH7MEDIUM14LOW5

Vulnerabilities

Page 1 of 2
CVE-2016-5311HIGHCVSS 7.8fixed in 22.72020-01-09
CVE-2016-5311 [HIGH] CWE-427 CVE-2016-5311: A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Back A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malic
nvd
CVE-2010-0107CRITICALCVSS 9.3v2006v2007+1 more2010-02-23
CVE-2010-0107 [CRITICAL] CWE-119 CVE-2010-0107: Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet S Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown
nvd
CVE-2009-3104MEDIUMCVSS 4.3v2005v2006+2 more2009-09-08
CVE-2009-3104 [MEDIUM] CWE-399 CVE-2009-3104: Unspecified vulnerability in Symantec Norton AntiVirus 2005 through 2008; Norton Internet Security 2 Unspecified vulnerability in Symantec Norton AntiVirus 2005 through 2008; Norton Internet Security 2005 through 2008; AntiVirus Corporate Edition 9.0 before MR7, 10.0, 10.1 before MR8, and 10.2 before MR3; and Client Security 2.0 before MR7, 3.0, and 3.1 before MR8; when Internet Email Scanning is installed and enabled, allows remote attackers to caus
nvd
CVE-2009-1428MEDIUMCVSS 4.3v2005v2005_contains_nav_11.0.0+3 more2009-04-29
CVE-2009-1428 [MEDIUM] CWE-79 CVE-2009-1428: Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as u Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail m
nvd
CVE-2008-0312CRITICALCVSS 9.3v2006v2007+1 more2008-04-08
CVE-2008-0312 [CRITICAL] CWE-119 CVE-2008-0312: Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in m Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogI
nvd
CVE-2008-0313MEDIUMCVSS 6.8v2006v2007+1 more2008-04-08
CVE-2008-0313 [MEDIUM] CVE-2008-0313: The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote at
nvd
CVE-2007-5829MEDIUMCVSS 6.0v3.02007-11-05
CVE-2007-5829 [MEDIUM] CWE-264 CVE-2007-5829: The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macint The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which are executed when a user with physic
nvd
CVE-2007-3699CRITICALCVSS 9.3v3.0v2004+2 more2007-10-05
CVE-2007-3699 [CRITICAL] CVE-2007-3699: The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
nvd
CVE-2007-0447CRITICALCVSS 9.3v3.0v2004+2 more2007-10-05
CVE-2007-0447 [CRITICAL] CWE-119 CVE-2007-0447: Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote a Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
nvd
CVE-2007-5047HIGHCVSS 7.2v2008_15.0.0.602007-09-24
CVE-2007-5047 [HIGH] CVE-2007-5047: Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Serv Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent function hooks are already covered by CVE-20
nvd
CVE-2007-2955MEDIUMCVSS 6.8v2005v20062007-08-09
CVE-2007-2955 [MEDIUM] CVE-2007-2955: Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavCom Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA.
nvd
CVE-2007-3673MEDIUMCVSS 6.9PoCv2005v20062007-07-15
CVE-2007-3673 [MEDIUM] CVE-2007-3673: Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 1 Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323
nvd
CVE-2007-1689CRITICALCVSS 10.0PoCv20042007-05-16
CVE-2007-1689 [CRITICAL] CVE-2007-1689: Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2 Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
nvd
CVE-2006-3456HIGHCVSS 8.5v2005v20062007-05-11
CVE-2006-3456 [HIGH] CWE-94 CVE-2006-3456: The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as us The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and pla
nvd
CVE-2007-1793MEDIUMCVSS 4.9PoCv2004v2005+3 more2007-04-02
CVE-2007-1793 [MEDIUM] CWE-20 CVE-2007-1793: SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certai SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was
nvd
CVE-2007-1476LOWCVSS 1.9PoCv2005v20062007-03-16
CVE-2007-1476 [LOW] CVE-2007-1476: The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access
nvd
CVE-2006-6490CRITICALCVSS 10.0v20062007-02-22
CVE-2006-6490 [CRITICAL] CVE-2006-6490: Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgct Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
nvd
CVE-2006-5403MEDIUMCVSS 5.1v20062006-10-19
CVE-2006-5403 [MEDIUM] CVE-2006-5403: Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as u Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2006-5404LOWCVSS 2.6v20062006-10-19
CVE-2006-5404 [LOW] CVE-2006-5404: Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as use Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2006-4855MEDIUMCVSS 4.9PoCv2003v2004+3 more2006-09-19
CVE-2006-4855 [MEDIUM] CWE-399 CVE-2006-4855: The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions o The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows loc
nvd