Page 3 of 36 results (0.009 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

20 Oct 2005 — Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file. • http://secunia.com/advisories/17268 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

02 Sep 2005 — Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server. • http://marc.info/?l=bugtraq&m=112552401413998&w=2 •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

29 Aug 2005 — Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540. • http://www.idefense.com/application/poi/display?id=298&type=vulnerabilities •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

29 Mar 2005 — Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type. • http://secunia.com/advisories/14741 •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

29 Mar 2005 — The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share. • http://secunia.com/advisories/14741 •

CVSS: 8.8EPSS: 1%CPEs: 49EXPL: 0

08 Feb 2005 — Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. • http://securitytracker.com/id?1013133 •

CVSS: 7.5EPSS: 0%CPEs: 16EXPL: 0

31 Dec 2004 — Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body. • http://www.securityfocus.com/archive/82/376487/2004-09-24/2004-09-30/0 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

06 Oct 2004 — Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name. Symantec Norton Antivirus 2004 y versiones anteriores permiten a un virus u otro código malicioso evitar ser detectados o causar una denegación de servicio (caída de aplicación) usando un nombre de fichero que contenga un nombre de dispositivo de MS-DOS. • http://www.idefense.com/application/poi/display?id=147&type=vulnerabilities •

CVSS: 10.0EPSS: 24%CPEs: 1EXPL: 0

03 Jun 2004 — A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs. Un cierto control ActiveX en Symantec Norton Antivirus 2004 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar programas de su elección. • http://marc.info/?l=bugtraq&m=108515369718455&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 23EXPL: 0

03 Feb 2004 — The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges. La funcionalidad gui para una sesión interactiva en ymantec LiveUpdate 1.70.x hasta la 1.90.x (usadas en Norton Internet Security 2001 hasta 2004, SystemWorks 2001 hasta 2004, y AntiVirus y Norton ... • http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html •