cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2016-5311,https://securityvulnerability.io/vulnerability/CVE-2016-5311,Privilege Escalation Vulnerability in Symantec Norton Products,"A privilege escalation vulnerability has been identified in a range of Symantec Norton products, stemming from improper DLL preloading that lacks appropriate path restrictions. This security flaw could enable a local malicious user to gain unauthorized system privileges, potentially allowing them to execute arbitrary code with elevated rights, thereby compromising the affected system's integrity and security.",Symantec,"Norton Antivirus, Norton Antivirus With Backup, Norton Security, Norton Security With Backup, Norton Internet Security, Norton 360,Endpoint Protection Small Business Edition Cloud, And Endpoint Protection Cloud Client",7.8,HIGH,0.0022799998987466097,false,,false,false,false,,,false,false,,2020-01-09T19:30:52.000Z,0 CVE-2011-3477,https://securityvulnerability.io/vulnerability/CVE-2011-3477,,"GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.",Symantec,"Norton 360,Norton Ghost,Backup Exec System Recovery,System Recovery 2011",5.5,MEDIUM,0.0004299999854993075,false,,false,false,false,,,false,false,,2018-02-19T19:00:00.000Z,0 CVE-2010-0107,https://securityvulnerability.io/vulnerability/CVE-2010-0107,,"Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can ""masquerade as an authorized site.""",Symantec,"Client Security,Norton Internet Security,Norton 360,Norton Antivirus",,,0.047210000455379486,false,,false,false,false,,,false,false,,2010-02-23T20:00:00.000Z,0 CVE-2009-1428,https://securityvulnerability.io/vulnerability/CVE-2009-1428,,"Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to ""two parsing errors.""",Symantec,"Norton Internet Security,Antivirus,Endpoint Protection,Norton 360",,,0.011789999902248383,false,,false,false,false,,,false,false,,2009-04-29T15:00:00.000Z,0 CVE-2008-0312,https://securityvulnerability.io/vulnerability/CVE-2008-0312,,"Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method. NOTE: some of these details are obtained from third party information.",Symantec,"Norton 360,Norton Antivirus,Norton Internet Security,Norton System Works",,,0.07197000086307526,false,,false,false,false,,,false,false,,2008-04-08T17:00:00.000Z,0 CVE-2008-0313,https://securityvulnerability.io/vulnerability/CVE-2008-0313,,"The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.",Symantec,"Norton Internet Security,Norton Antivirus,System Works,Norton 360",,,0.009469999931752682,false,,false,false,false,,,false,false,,2008-04-08T17:00:00.000Z,0 CVE-2007-1793,https://securityvulnerability.io/vulnerability/CVE-2007-1793,,"SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.",Symantec,"Client Security,Antivirus,Norton Internet Security,Norton System Works,Norton Antivirus,Norton Personal Firewall,Norton Antispam,Norton 360",,,0.0006600000197067857,false,,false,false,false,,,false,false,,2007-04-02T22:00:00.000Z,0