cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-23617,https://securityvulnerability.io/vulnerability/CVE-2024-23617,Symantec Data Loss Prevention Buffer Overflow,"A buffer overflow vulnerability has been identified in Symantec Data Loss Prevention, specifically in version 14.0.2 and prior versions. This security issue allows a remote, unauthenticated attacker to exploit the system by convincing a user to open a specially crafted document. If successful, this exploitation could lead to unauthorized code execution on the victim's machine, potentially compromising sensitive data and impacting overall system integrity. Organizations relying on this software should evaluate their current version and take necessary precautions to mitigate potential risks.",Symantec,Data Loss Prevention,8.8,HIGH,0.0056500001810491085,false,,false,false,false,,,false,false,,2024-01-26T00:15:00.000Z,0 CVE-2019-9701,https://securityvulnerability.io/vulnerability/CVE-2019-9701,Cross-Site Scripting Vulnerability in Symantec DLP Software,"The Symantec Data Loss Prevention (DLP) 15.5 MP1 and earlier versions are vulnerable to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious client-side scripts into web pages viewed by other users. Exploiting this weakness could enable attackers to bypass security measures such as the same-origin policy, leading to unauthorized actions on behalf of the user. It is crucial for organizations using affected versions to apply security patches and implement web application security best practices to mitigate potential risks.",Symantec,Data Loss Prevention,4.8,MEDIUM,0.9537400007247925,false,,false,false,false,,,false,false,,2019-06-19T15:55:27.000Z,0 CVE-2014-9230,https://securityvulnerability.io/vulnerability/CVE-2014-9230,,Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.,Symantec,Data Loss Prevention,,,0.007249999791383743,false,,false,false,false,,,false,false,,2015-06-28T19:00:00.000Z,0 CVE-2015-1485,https://securityvulnerability.io/vulnerability/CVE-2015-1485,,Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.,Symantec,Data Loss Prevention,,,0.0011899999808520079,false,,false,false,false,,,false,false,,2015-06-28T19:00:00.000Z,0 CVE-2009-3032,https://securityvulnerability.io/vulnerability/CVE-2009-3032,,"Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.",Symantec,"Data Loss Prevention Detection Servers,Mail Security,Im Manager 2007,Lotus Notes,Data Loss Prevention Endpoint Agents,Brightmail Gateway",,,0.003160000080242753,false,,false,false,false,,,false,false,,2010-03-05T19:00:00.000Z,0 CVE-2008-4564,https://securityvulnerability.io/vulnerability/CVE-2008-4564,,"Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.",Symantec,"Data Loss Prevention Detection Servers,Keyview Filter Sdk,Lotus Notes,Mail Security,Keyview Export Sdk,Enforce,Keyview Viewer Sdk,Data Loss Prevention Endpoint Agents,Altiris Deployment Solution,Brightmail",,,0.957889974117279,false,,false,false,false,,,false,false,,2009-03-18T15:00:00.000Z,0