Symantec Norton Security vulnerabilities
10 known vulnerabilities affecting symantec/norton_security.
Total CVEs
10
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-5311HIGHCVSS 7.8fixed in 22.72020-01-09
CVE-2016-5311 [HIGH] CWE-427 CVE-2016-5311: A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Back
A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malic
nvd
CVE-2018-18369HIGHCVSS 7.8fixed in 22.16.32019-04-25
CVE-2018-18369 [HIGH] CWE-426 CVE-2018-18369: Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead
nvd
CVE-2018-18366MEDIUMCVSS 6.5fixed in 22.16.32019-04-25
CVE-2018-18366 [MEDIUM] CWE-908 CVE-2018-18366: Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9,
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can c
nvd
CVE-2016-3645CRITICALCVSS 9.8PoC≤ 13.0.12016-06-30
CVE-2016-3645 [CRITICAL] CWE-189 CVE-2016-3645: Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linu
nvd
CVE-2016-3646HIGHCVSS 8.4PoC≤ 13.0.12016-06-30
CVE-2016-3646 [HIGH] CWE-20 CVE-2016-3646: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-2207HIGHCVSS 8.4PoC≤ 13.0.12016-06-30
CVE-2016-2207 [HIGH] CWE-20 CVE-2016-2207: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-3644HIGHCVSS 8.4PoC≤ 13.0.12016-06-30
CVE-2016-3644 [HIGH] CWE-20 CVE-2016-3644: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Eng
nvd
CVE-2016-2211HIGHCVSS 7.8≤ 13.0.12016-06-30
CVE-2016-2211 [HIGH] CWE-119 CVE-2016-2211: The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center S
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection En
nvd
CVE-2016-2210HIGHCVSS 7.3PoC≤ 13.0.12016-06-30
CVE-2016-2210 [HIGH] CWE-119 CVE-2016-2210: Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protec
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12
nvd
CVE-2016-2209HIGHCVSS 7.3PoC≤ 13.0.12016-06-30
CVE-2016-2209 [HIGH] CWE-119 CVE-2016-2209: Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protect
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.
nvd