Symantec Corporation Symantec Endpoint Protection vulnerabilities

7 known vulnerabilities affecting symantec_corporation/symantec_endpoint_protection.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2018-12244MEDIUMCVSS 6.3vPrior to and including 12.1 RU6 MP9vPrior to 14.2 RU12019-04-25
CVE-2018-12244 [MEDIUM] CWE-1236 CVE-2018-12244: SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a C SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
cvelistv5nvd
CVE-2018-12245HIGHCVSS 7.8vPrior to 14.2 MP12018-11-29
CVE-2018-12245 [HIGH] CWE-426 CVE-2018-12245: Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time; no remediation is required for sof
cvelistv5nvd
CVE-2018-5237HIGHCVSS 8.8vPrior to 14 RU1 MP1 or 12.1 RU6 MP102018-06-20
CVE-2018-5237 [HIGH] CVE-2018-5237: Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privileg Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
cvelistv5nvd
CVE-2018-5236MEDIUMCVSS 5.3vPrior to 14 RU1 MP1 or 12.1 RU6 MP102018-06-20
CVE-2018-5236 [MEDIUM] CWE-362 CVE-2018-5236: Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condi Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.
cvelistv5nvd
CVE-2017-13681HIGHCVSS 7.8vPrior to SEP 12.1 RU6 MP92017-11-06
CVE-2017-13681 [HIGH] CVE-2017-13681: Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalatio Symantec Endpoint Protection prior to SEP 12.1 RU6 MP9 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. In the circumstances of this issue, the capability of exploit is limited by the need to perform multiple file a
cvelistv5nvd
CVE-2017-6331HIGHCVSS 7.1PoCvPrior to SEP 14 RU12017-11-06
CVE-2017-6331 [HIGH] CVE-2017-6331: Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.
cvelistv5nvd
CVE-2017-13680MEDIUMCVSS 5.5vPrior to SEP 12.1 RU6 MP9 & SEP 14 RU12017-11-06
CVE-2017-13680 [MEDIUM] CVE-2017-13680: Prior to SEP 12.1 RU6 MP9 & SEP 14 RU1 Symantec Endpoint Protection Windows endpoint can encounter a Prior to SEP 12.1 RU6 MP9 & SEP 14 RU1 Symantec Endpoint Protection Windows endpoint can encounter a situation whereby an attacker could use the product's UI to perform unauthorized file deletes on the resident file system.
cvelistv5nvd