Symantec Norton Password Manager vulnerabilities

4 known vulnerabilities affecting symantec/norton_password_manager.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2019-12755MEDIUMCVSS 5.5fixed in 6.5.0.21042019-09-17
CVE-2019-12755 [MEDIUM] CVE-2019-12755: Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
nvd
CVE-2018-18365HIGHCVSS 7.5fixed in 6.2.0.1078fixed in 6.2.3092019-04-09
CVE-2018-18365 [HIGH] CVE-2018-18365: Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allo Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic.
nvd
CVE-2018-18362MEDIUMCVSS 6.1fixed in 6.1.0.10452018-12-06
CVE-2018-18362 [MEDIUM] CWE-79 CVE-2018-18362: Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross si Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such
nvd
CVE-2018-12240MEDIUMCVSS 5.9fixed in 5.3.0.9762018-08-29
CVE-2018-12240 [MEDIUM] CWE-798 CVE-2018-12240: The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation iss The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.
nvd