Symantec

10 February

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and ea ...

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, ...

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash v ...

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive dur ...

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denia ...

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a den ...

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Repor ...

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 an ...

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remot ...

08 February

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to ...

Óâåäîìëåíèÿ 1 - 23 of 188
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 | Next | Last 

SYM10-012: Security Advisories Relating to Symantec Products - PGP Desktop Unsigned Data Insertion

PGP Desktop versions are vulnerable to a data insertion vulnerability.

22 november, 2010

SYM10-009: Multi-Vendor Autonomy KeyView Filter Multiple Security Issues

Symantec products that ship with the Verity KeyView Filter have updated the module to address multiple security issues being reported in the content filter processing of specifically crafted document formats.

28 july, 2010

SYM10-001: Security Advisories Relating to Symantec Products - Symantec Altiris Notification Server 6.x Static Encryption Key

Symantec’s Altiris Notification Server 6.0.x web console stores a static encryption key for encrypted credentials entered by the administrator.

01 february, 2010

SYM09-016: Security Advisories Relating to Symantec Products - Symantec’s Altiris Deployment and Notification Management Web Console RunCmd Vulnerability

Symantec’s Altiris Deployment Solution, Notification Server and Symantec Management Platform web consoles install a vulnerable ActiveX control.

25 november, 2009

SYM09-013: Security Advisories Relating to Symantec Products - Symantec Altiris Deployment Solution and Notification Server Management Console FileDownload Vulnerability

Exploitation of this issue could possibly lead to unauthorized information disclosure, system information corruption or potentially allow arbitrary code execution in the context of the user’s browser.

03 november, 2009

SYM09-015: Security Advisories Relating to Symantec Products - Symantec Altiris Deployment Solution and Notification Server Management Web Console BrowseandSave ActiveX Overflow

Exploitation of this issue could possibly lead to unauthorized information disclosure, system information corruption or potentially allow arbitrary code execution in the context of the user’s browser. Successful exploitation requires user interaction.

03 november, 2009

SYM09-012: Security Advisories Relating to Symantec Products - Norton AntiVirus and Symantec Client Security Email Denial of Service Vulnerability

Norton AntiVirus and Symantec Client Security are susceptible to an email denial of Service (DoS) attack which could be triggered by a specially crafted email message.

01 september, 2009

SYM09-011: Security Advisories Relating to Symantec Products - Symantec Altiris Deployment Solution Multiple Vulnerabilities

Symantec’s Altiris Deployment Solution contains vulnerabilities that could potentially be leveraged for unauthorized file access or a denial of service on a client system, authentication bypass on the Server to local system-level access on a client system.

01 september, 2009

SYM09-010: Symantec Products Autonomy KeyView Module Vulnerability

Symantec products that ship a third-party Autonomy KeyView module have updated the module to address a vulnerability in the processing of Excel spreadsheets reported against the KeyView module.

26 august, 2009

SYM09-008: Security Advisories Relating to Symantec Products - Symantec Reporting Server Improper URL Handling Exposure

The login web page in some versions of Symantec Reporting Server contains a URL handling error which could potentially allow an attacker to launch a phishing attack.

18 may, 2009

SYM09-006: Security Advisories Relating to Symantec Products - Symantec Log Viewer JavaScript Injection Vulnerabilities

The Log Viewer feature in some Symantec products contains two parsing errors which could be exploited through Java script injection.

18 may, 2009

SYM09-007: Security Advisories Relating to Symantec Products - Symantec Alert Management System 2 multiple vulnerabilities

The version of Alert Management System 2 (AMS2) used by some versions of Symantec System Center, Symantec Antivirus Server, and Symantec AntiVirus Central Quarantine Server contains four vulnerabilities.

13 may, 2009

SYM09-005: Security Advisories Relating to Symantec Products - Symantec Brightmail Gateway and Mail Security Appliance Cross-site Scripting and Elevation of Privilege

Symantec product engineers have released an update for these issues in all affected product versions.

09 may, 2009

SYM09-004: Symantec Products Update Vulnerable Autonomy KeyView Module

Symantec products that ship and use a third-party Autonomy KeyView module have updated the module to address a buffer overflow vulnerability reported against the KeyView module.

26 march, 2009

SYM09-003: Symantec pcAnywhere Format String Denial of Service

An authorized local user may potentially leverage this to crash the pcAnywhere application, leading to a denial of service.

19 march, 2009

SYM09-002: Symantec NetBackup Communications Setup Elevation of Privilege

A non-privileged but authorized system user could potentially leverage the Veritas Network daemon to attempt to gain elevated privileges on the system.

19 february, 2009

SYM09-001: Symantec AppStream ActiveX Unauthorized Access

Exploitation of this issue could possibly lead to unauthorized information disclosure, system information corruption or potentially allow arbitrary code execution in the context of the user’s browser.

31 january, 2009

SYM08-022: Symantec SPBBCDRV.SYS Device Driver Local Denial of Service

Some versions of Symantec’s device driver SPBBCDRV.SYS contain a vulnerability which, if successfully exploited, could allow a local attacker to cause the system to crash.

18 december, 2008

SYM08-021: Symantec Backup Exec Authentication Bypass and Potential Buffer Overflow

Vulnerabilities were found in the authentication methods for logging onto a Backup Exec Remote Agent for Windows, Linux/Unix, Macintosh and Remote Media Agent for Linux Servers, that could allow an unprivileged user to gain unauthorized access to the application.

20 november, 2008

SYM08-018: Veritas File System Quick I/O for Database Utility Information Disclosure and Elevation of Privilege

A potential for sensitive information to be disclosed has been identified and resolved in the Quick I/O for Database feature of Veritas File System (VxFS).

22 october, 2008

SYM08-020: Symantec Altiris Deployment Solution Elevation of Privilege Clear Text Password in Memory

An elevation of privilege issue via a privileged access password stored in memory has been identified and resolved in the Symantec Altiris Deployment Solution.

22 october, 2008

SYM08-019: Symantec Altiris Deployment Solution Local Access Elevation of Privilege in Client GUI

A local access elevation of privilege issue has been identified and resolved in the Symantec Altiris Deployment Solution Client GUI.

22 october, 2008

SYM08-016: Symantec Veritas NetBackup Administration JAVA GUI Elevation of Privilege

A non-privileged but authorized user could potentially leverage Symantec Veritas NetBackup JAVA Administration Graphical User Interface (GUI) to execute code with elevated privileges on the server.

26 september, 2008

Óâåäîìëåíèÿ 1 - 23 of 188
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 12 | Next | Last

CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

10 february, 2012

CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trig ...

10 february, 2012

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CP ...

10 february, 2012

CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to m ...

10 february, 2012

CVE-2011-4534

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of connections and disconnections on TCP port 1101, aka Reference Numb ...

10 february, 2012

CVE-2011-4533

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted packet to TCP port 50777, aka Reference Number 25240.

10 february, 2012

CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access vi ...

10 february, 2012

CVE-2011-4038

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via uns ...

10 february, 2012

CVE-2012-1046

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.

10 february, 2012

CVE-2011-3972

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

08 february, 2012

MS12-004 midiOutPlayNextPolyEvent Heap Overflow Exploit

Target: Microsoft Windows Media
Impact: Code execution

ActFax Server FTP RETR Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution

ActFax Server (LPD/LPR) Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution