CVE-2014-7287
https://notcve.org/view.php?id=CVE-2014-7287
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header. El componente de la gestión de claves en Symantec PGP Universal Server y Encryption Management Server anterior a 3.3.2 MP7 permite a atacantes remotos provocar contenido no intencionado en mensajes de email salientes a través de un valor de clave UID manipulado en un mensaje de email entrante, tal y como fue demostrado por la cabecera del asunto saliente. • http://www.securityfocus.com/bid/72307 http://www.securitytracker.com/id/1031673 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150129_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/100762 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2014-7288 – Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
https://notcve.org/view.php?id=CVE-2014-7288
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action. Symantec PGP Universal Server y Encryption Management Server anterior a 3.3.2 MP7 permiten a administradores remotos autenticados ejecutar comandos de shell arbitrarios a través de una línea de comandos manipulada en una acción de restauración de la copia de seguridad de la base de datos. Symantec Encryption Gateway suffers from a remote command injection vulnerability. Versions prior to 3.2.0 MP6 are affected. • https://www.exploit-db.com/exploits/35949 http://www.exploit-db.com/exploits/35949 http://www.osvdb.org/117766 http://www.securityfocus.com/bid/72308 http://www.securitytracker.com/id/1031673 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150129_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/100763 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-4674
https://notcve.org/view.php?id=CVE-2013-4674
Cross-site scripting (XSS) vulnerability in the Web Email Protection component in Symantec Encryption Management Server (formerly Symantec PGP Universal Server) before 3.3.0 MP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted encrypted e-mail attachment. Vulnerabilidad XSS en el componente Email Protection en Symantec Encryption Management Server (anteriormente Symantec PGP Universal Server) anterior a 3.3.0 MP2, permite a usuarios autenticados remotamente la inyección arbitraria de código HTML o web a través de un adjunto de correo cifrado. • http://osvdb.org/95581 http://secunia.com/advisories/54214 http://www.securityfocus.com/bid/61290 http://www.securitytracker.com/id/1028820 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130722_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/85902 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-3582
https://notcve.org/view.php?id=CVE-2012-3582
Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session. Symantec PGP Universal Server 3.2.x anterior a 3.2.1 MP2 no gestiona adecuadamente las sesiones que incluyen solicitudes de clave de búsqueda, permitiendo a atacantes remotos leer una clave privada en circunstancias oportunistas haciendo una petición casi al final de la sesión de un usuario. • http://www.securityfocus.com/bid/55246 http://www.securitytracker.com/id?1027467 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120830_00 • CWE-264: Permissions, Privileges, and Access Controls •