cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2019-12759,https://securityvulnerability.io/vulnerability/CVE-2019-12759,Privilege Escalation Vulnerability in Symantec Endpoint Protection Manager and Mail Security for MS Exchange,"Symantec Endpoint Protection Manager and Symantec Mail Security for MS Exchange exhibit a vulnerability that allows attackers to exploit weaknesses in the software. If successful, an attacker could gain unauthorized elevated access to sensitive resources, potentially compromising critical data and operational integrity. Users of these products are advised to update to the latest versions to mitigate the risk.",Symantec,"Symantec Endpoint Protection Manager (sepm), Symantec Mail Security For Ms Exchange (smsmse)",7.8,HIGH,0.0016400000313296914,false,,false,false,false,,,false,false,,2019-11-15T17:41:24.000Z,0 CVE-2016-5309,https://securityvulnerability.io/vulnerability/CVE-2016-5309,,"The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted RAR file that is mishandled during decompression.",Symantec,"Protection Engine,Protection For Sharepoint Servers,Mail Security For Microsoft Exchange,Messaging Gateway,Mail Security For Domino,Endpoint Protection,Endpoint Protection For Small Business,Web Security.cloud,Messaging Gateway For Service Providers,Advanced Threat Protection,Email Security.cloud,Endpoint Protection Cloud,CSAPi,Web Gateway,Symantec Data Center Security Server",5.5,MEDIUM,0.0030300000216811895,false,,false,false,false,,,false,false,,2017-04-14T18:00:00.000Z,0 CVE-2016-5310,https://securityvulnerability.io/vulnerability/CVE-2016-5310,,"The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (memory corruption) via a crafted RAR file that is mishandled during decompression.",Symantec,"Protection Engine,Protection For Sharepoint Servers,Mail Security For Microsoft Exchange,Messaging Gateway,Mail Security For Domino,Endpoint Protection,Endpoint Protection For Small Business,Web Security.cloud,Messaging Gateway For Service Providers,Advanced Threat Protection,Email Security.cloud,Endpoint Protection Cloud,CSAPi,Web Gateway,Symantec Data Center Security Server",5.5,MEDIUM,0.0062500000931322575,false,,false,false,false,,,false,false,,2017-04-14T18:00:00.000Z,0 CVE-2016-2207,https://securityvulnerability.io/vulnerability/CVE-2016-2207,,"The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation) via a crafted RAR file that is mishandled during decompression.",Symantec,Mail Security For Microsoft Exchange,8.4,HIGH,0.7386000156402588,false,,false,false,false,,,false,false,,2016-06-30T23:59:00.000Z,0 CVE-2016-2210,https://securityvulnerability.io/vulnerability/CVE-2016-2210,,"Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.",Symantec,Mail Security For Microsoft Exchange,7.3,HIGH,0.1120000034570694,false,,false,false,false,,,false,false,,2016-06-30T23:59:00.000Z,0 CVE-2016-2209,https://securityvulnerability.io/vulnerability/CVE-2016-2209,,"Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.",Symantec,Mail Security For Microsoft Exchange,7.3,HIGH,0.1120000034570694,false,,false,false,false,,,false,false,,2016-06-30T23:59:00.000Z,0 CVE-2016-2211,https://securityvulnerability.io/vulnerability/CVE-2016-2211,,"The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CAB file that is mishandled during decompression.",Symantec,Mail Security For Microsoft Exchange,7.8,HIGH,0.11031000316143036,false,,false,false,false,,,false,false,,2016-06-30T23:59:00.000Z,0 CVE-2011-0548,https://securityvulnerability.io/vulnerability/CVE-2011-0548,,"Buffer overflow in the Lotus Freelance Graphics PRZ file viewer in Autonomy KeyView, as used in Symantec Mail Security (SMS) 6.x through 8.x, Symantec Brightmail and Messaging Gateway before 9.5.1, and Symantec Data Loss Prevention (DLP) before 10.5.3 and 11.x before 11.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .prz file. NOTE: this may overlap CVE-2011-1217.",Symantec,Mail Security,,,0.025609999895095825,false,,false,false,false,,,false,false,,2011-07-18T22:00:00.000Z,0 CVE-2009-3032,https://securityvulnerability.io/vulnerability/CVE-2009-3032,,"Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.",Symantec,"Data Loss Prevention Detection Servers,Mail Security,Im Manager 2007,Lotus Notes,Data Loss Prevention Endpoint Agents,Brightmail Gateway",,,0.003160000080242753,false,,false,false,false,,,false,false,,2010-03-05T19:00:00.000Z,0 CVE-2008-4564,https://securityvulnerability.io/vulnerability/CVE-2008-4564,,"Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.",Symantec,"Data Loss Prevention Detection Servers,Keyview Filter Sdk,Lotus Notes,Mail Security,Keyview Export Sdk,Enforce,Keyview Viewer Sdk,Data Loss Prevention Endpoint Agents,Altiris Deployment Solution,Brightmail",,,0.957889974117279,false,,false,false,false,,,false,false,,2009-03-18T15:00:00.000Z,0 CVE-2008-0309,https://securityvulnerability.io/vulnerability/CVE-2008-0309,,"Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).",Symantec,"Symantec Antivirus Filtering Domino Mpe,Symantec Mail Security For Microsoft Exchange,Symantec Antivirus Scan Engine For Ms Isa,Symantec Antivirus Scan Engine Clearswift,Symantec Antivirus Scan Engine,Scan Engine,Symantec Antivirus Scan Engine For Microsoft Sharepoint,Symantec Antivirus Scan Engine Messaging,Symantec Antivirus Scan Engine Caching,Symantec Antivirus Network Attached Storage",,,0.09509000182151794,false,,false,false,false,,,false,false,,2008-02-28T20:00:00.000Z,0 CVE-2008-0308,https://securityvulnerability.io/vulnerability/CVE-2008-0308,,"Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).",Symantec,"Symantec Antivirus Filtering Domino Mpe,Symantec Antivirus Ms Isa,Symantec Antivirus Scan Engine,Symantec Antivirus Messaging,Scan Engine,Symantec Antivirus Microsoft Sharepoint,Symantec Mail Security Exchange,Symantec Antivirus Clearswift,Symantec Antivirus Scan Engine Caching,Symantec Antivirus Network Attached Storage",,,0.014990000054240227,false,,false,false,false,,,false,false,,2008-02-28T20:00:00.000Z,0 CVE-2007-5910,https://securityvulnerability.io/vulnerability/CVE-2007-5910,,"Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.",Symantec,"Mail Security,Lotus Notes,Keyview Viewer Sdk,Docconverter,Keyview Filter Sdk,Keyview Export Sdk",,,0.20374999940395355,false,,false,false,false,,,false,false,,2007-11-10T02:00:00.000Z,0 CVE-2007-5909,https://securityvulnerability.io/vulnerability/CVE-2007-5909,,"Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.",Symantec,"Mail Security,Lotus Notes,Keyview Viewer Sdk,Docconverter,Keyview Filter Sdk,Keyview Export Sdk",,,0.5366899967193604,false,,false,false,false,,,false,false,,2007-11-10T02:00:00.000Z,0 CVE-2007-3699,https://securityvulnerability.io/vulnerability/CVE-2007-3699,,The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.,Symantec,"Mail Security,Client Security,Norton Antivirus,Norton Internet Security,Antivirus Scan Engine,Web Security,Brightmail Antispam,Norton System Works,Symantec Antivirus Filtering \+for Domino,Norton Personal Firewall",,,0.0521400012075901,false,,false,false,false,,,false,false,,2007-10-05T21:00:00.000Z,0 CVE-2007-0447,https://securityvulnerability.io/vulnerability/CVE-2007-0447,,Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.,Symantec,"Mail Security,Client Security,Norton Antivirus,Norton Internet Security,Antivirus Scan Engine,Web Security,Brightmail Antispam,Norton System Works,Symantec Antivirus Filtering \+for Domino,Norton Personal Firewall",,,0.1824599951505661,false,,false,false,false,,,false,false,,2007-10-05T21:00:00.000Z,0 CVE-2007-1792,https://securityvulnerability.io/vulnerability/CVE-2007-1792,,"libdayzero.dll in the Filter Hub Service (filter-hub.exe) in Symantec Mail Security for SMTP before 5.0.1 Patch 181 and Mail Security Appliance before 5.0.0-36 allows remote attackers to cause a denial of service (crash) via a crafted executable attachment in an e-mail, involving the detection of ""PE-Shield v0.2"" and ""ASPack v1.00-1.08.02"".",Symantec,Mail Security,,,0.003269999986514449,false,,false,false,false,,,false,false,,2007-06-27T17:00:00.000Z,0 CVE-2007-1252,https://securityvulnerability.io/vulnerability/CVE-2007-1252,,Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message. NOTE: some information was obtained from third party sources.,Symantec,Mail Security,,,0.24463999271392822,false,,false,false,false,,,false,false,,2007-03-03T20:00:00.000Z,0 CVE-2006-5545,https://securityvulnerability.io/vulnerability/CVE-2006-5545,,"Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.",Symantec,Mail Security,,,0.24961000680923462,false,,false,false,false,,,false,false,,2006-10-26T17:00:00.000Z,0 CVE-2005-1346,https://securityvulnerability.io/vulnerability/CVE-2005-1346,,"Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.",Symantec,"Norton Internet Security,Symav Filter Domino Nt,Mail Security,Antivirus Scan Engine,Web Security,Norton Antivirus,Norton System Works",,,0.002689999993890524,false,,false,false,false,,,false,false,,2005-05-02T04:00:00.000Z,0 CVE-2005-0249,https://securityvulnerability.io/vulnerability/CVE-2005-0249,,Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.,Symantec,"Norton Internet Security,Client Security,Mail Security,Norton Antivirus,Sav Filter Domino Nt Ports,Web Security,Norton System Works,Brightmail Antispam,Gateway Security,Sav Filter For Domino Nt,Antivirus Scan Engine",,,0.01566999964416027,false,,false,false,false,,,false,false,,2005-02-08T05:00:00.000Z,0