Symantec Reporting Server vulnerabilities
3 known vulnerabilities affecting symantec/reporting_server.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2007-3095CRITICALCVSS 9.0≤ 1.0.197.02007-06-06
CVE-2007-3095 [CRITICAL] CVE-2007-3095: Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.
Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown vectors.
nvd
CVE-2007-3021HIGHCVSS 7.5≤ 1.0.197.02007-06-05
CVE-2007-3021 [HIGH] CVE-2007-3021: Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export.
nvd
CVE-2007-3022MEDIUMCVSS 4.3≤ 1.0.197.02007-06-05
CVE-2007-3022 [MEDIUM] CVE-2007-3022: Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.
nvd