Symantec Norton Personal Firewall vulnerabilities
18 known vulnerabilities affecting symantec/norton_personal_firewall.
Total CVEs
18
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH3MEDIUM7LOW4
Vulnerabilities
Page 1 of 1
CVE-2007-3699CRITICALCVSS 9.3v2006v2006_9.1.0.33+1 more2007-10-05
CVE-2007-3699 [CRITICAL] CVE-2007-3699: The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
nvd
CVE-2007-0447CRITICALCVSS 9.3v2006v2006_9.1.0.33+1 more2007-10-05
CVE-2007-0447 [CRITICAL] CWE-119 CVE-2007-0447: Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote a
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
nvd
CVE-2007-3673MEDIUMCVSS 6.9PoCv2005v20062007-07-15
CVE-2007-3673 [MEDIUM] CVE-2007-3673: Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 1
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323
nvd
CVE-2007-1689CRITICALCVSS 10.0PoCv20042007-05-16
CVE-2007-1689 [CRITICAL] CVE-2007-1689: Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
nvd
CVE-2007-1793MEDIUMCVSS 4.9PoCv2004v2005+3 more2007-04-02
CVE-2007-1793 [MEDIUM] CWE-20 CVE-2007-1793: SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certai
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was
nvd
CVE-2007-1495MEDIUMCVSS 4.9v2006_9.1.1.72007-03-16
CVE-2007-1495 [MEDIUM] CVE-2007-1495: The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other pr
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.
nvd
CVE-2007-1476LOWCVSS 1.9PoC≤ 2006_9.1.1.7v2005+2 more2007-03-16
CVE-2007-1476 [LOW] CVE-2007-1476: The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier,
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access
nvd
CVE-2006-4855MEDIUMCVSS 4.9PoCv2003v2004+2 more2006-09-19
CVE-2006-4855 [MEDIUM] CWE-399 CVE-2006-4855: The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions o
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows loc
nvd
CVE-2006-4266LOWCVSS 3.6≤ 2006_9.1.0.332006-08-21
CVE-2006-4266 [LOW] CVE-2006-4266: Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Nor
Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegRestoreKey to modify HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners, as demonstrated using NISProd.dll. NOTE: in most cases, this attack would not cross pri
nvd
CVE-2006-3725LOWCVSS 2.1v2006_9.1.0.332006-07-21
CVE-2006-3725 [LOW] CVE-2006-3725: Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via c
Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent registry keys.
nvd
CVE-2006-1836MEDIUMCVSS 6.8v3.0v3.12006-04-19
CVE-2006-1836 [MEDIUM] CVE-2006-1836: Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
nvd
CVE-2004-0375MEDIUMCVSS 5.0PoCv2003v20042004-08-18
CVE-2004-0375 [MEDIUM] CVE-2004-0375: SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 20
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.
nvd
CVE-2004-0444CRITICALCVSS 10.0v2002v2003+1 more2004-07-07
CVE-2004-0444 [CRITICAL] CVE-2004-0444: Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 t
Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte
nvd
CVE-2004-0445LOWCVSS 2.6PoCv2002v2003+1 more2004-07-07
CVE-2004-0445 [LOW] CVE-2004-0445: The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norto
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name poi
nvd
CVE-2002-1779HIGHCVSS 7.5v20022002-12-31
CVE-2002-1779 [HIGH] CVE-2002-1779: The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not pr
The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).
nvd
CVE-2002-1778HIGHCVSS 7.5v20022002-12-31
CVE-2002-1778 [HIGH] CVE-2002-1778: Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by
Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan.
nvd
CVE-2002-2336MEDIUMCVSS 4.3PoCv20022002-12-31
CVE-2002-2336 [MEDIUM] CWE-16 CVE-2002-2336: Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote att
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
nvd
CVE-2002-0663HIGHCVSS 7.5v2001_3.0.4.912002-07-26
CVE-2002-0663 [HIGH] CVE-2002-0663: Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Int
Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request.
nvd