Page 2 of 9 results (0.009 seconds)

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header. El componente de la gestión de claves en Symantec PGP Universal Server y Encryption Management Server anterior a 3.3.2 MP7 permite a atacantes remotos provocar contenido no intencionado en mensajes de email salientes a través de un valor de clave UID manipulado en un mensaje de email entrante, tal y como fue demostrado por la cabecera del asunto saliente. • http://www.securityfocus.com/bid/72307 http://www.securitytracker.com/id/1031673 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150129_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/100762 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 9.0EPSS: 10%CPEs: 2EXPL: 2

Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action. Symantec PGP Universal Server y Encryption Management Server anterior a 3.3.2 MP7 permiten a administradores remotos autenticados ejecutar comandos de shell arbitrarios a través de una línea de comandos manipulada en una acción de restauración de la copia de seguridad de la base de datos. Symantec Encryption Gateway suffers from a remote command injection vulnerability. Versions prior to 3.2.0 MP6 are affected. • https://www.exploit-db.com/exploits/35949 http://www.exploit-db.com/exploits/35949 http://www.osvdb.org/117766 http://www.securityfocus.com/bid/72308 http://www.securitytracker.com/id/1031673 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150129_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/100763 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 4EXPL: 0

The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL. El componente Web Email Protection en Symantec Encryption Management Server (también conocido como PGP Universal Server) anterior a 3.3.2 permite a usuarios remotos autenticados leer los e-mail de salida de usuarios arbitrarios a través de una URL modificada. Symantec PGP Universal Web Messenger versions prior to 3.3.2 suffer from an unauthorized access vulnerability. • http://www.securityfocus.com/bid/65300 http://www.securitytracker.com/id/1029729 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140205_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/90946 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment. Vulnerabilidad XSS en el componente Email Protection en Symantec Encryption Management Server (anteriormente Symantec PGP Universal Server) anterior a 3.3.0 MP2, permite a usuarios autenticados remotamente la inyección arbitraria de código HTML o web a través de un adjunto de correo cifrado. • http://osvdb.org/95581 http://secunia.com/advisories/54214 http://www.securityfocus.com/bid/61290 http://www.securitytracker.com/id/1028820 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130722_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/85902 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •