cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2016-5310,https://securityvulnerability.io/vulnerability/CVE-2016-5310,,"The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (memory corruption) via a crafted RAR file that is mishandled during decompression.",Symantec,"Protection Engine,Protection For Sharepoint Servers,Mail Security For Microsoft Exchange,Messaging Gateway,Mail Security For Domino,Endpoint Protection,Endpoint Protection For Small Business,Web Security.cloud,Messaging Gateway For Service Providers,Advanced Threat Protection,Email Security.cloud,Endpoint Protection Cloud,CSAPi,Web Gateway,Symantec Data Center Security Server",5.5,MEDIUM,0.0062500000931322575,false,,false,false,false,,,false,false,,2017-04-14T18:00:00.000Z,0 CVE-2016-5309,https://securityvulnerability.io/vulnerability/CVE-2016-5309,,"The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted RAR file that is mishandled during decompression.",Symantec,"Protection Engine,Protection For Sharepoint Servers,Mail Security For Microsoft Exchange,Messaging Gateway,Mail Security For Domino,Endpoint Protection,Endpoint Protection For Small Business,Web Security.cloud,Messaging Gateway For Service Providers,Advanced Threat Protection,Email Security.cloud,Endpoint Protection Cloud,CSAPi,Web Gateway,Symantec Data Center Security Server",5.5,MEDIUM,0.0030300000216811895,false,,false,false,false,,,false,false,,2017-04-14T18:00:00.000Z,0 CVE-2016-5313,https://securityvulnerability.io/vulnerability/CVE-2016-5313,,Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.,Symantec,Web Gateway,8.8,HIGH,0.38227999210357666,false,,false,false,false,,,false,false,,2017-04-12T22:00:00.000Z,0 CVE-2015-6547,https://securityvulnerability.io/vulnerability/CVE-2015-6547,,The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.,Symantec,Web Gateway,,,0.003019999945536256,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2015-5692,https://securityvulnerability.io/vulnerability/CVE-2015-5692,,"admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file.",Symantec,Web Gateway,,,0.0017500000540167093,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2015-5690,https://securityvulnerability.io/vulnerability/CVE-2015-5690,,"The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a ""redirect.""",Symantec,Web Gateway,,,0.005059999879449606,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2015-5691,https://securityvulnerability.io/vulnerability/CVE-2015-5691,,"Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.",Symantec,Web Gateway,,,0.6948800086975098,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2015-5693,https://securityvulnerability.io/vulnerability/CVE-2015-5693,,"The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to ""traffic capture.""",Symantec,Web Gateway,,,0.006029999814927578,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2015-6548,https://securityvulnerability.io/vulnerability/CVE-2015-6548,,Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.,Symantec,Web Gateway,,,0.0016499999910593033,false,,false,false,false,,,false,false,,2015-09-20T20:00:00.000Z,0 CVE-2014-7285,https://securityvulnerability.io/vulnerability/CVE-2014-7285,,The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.,Symantec,Web Gateway,,,0.5863900184631348,false,,false,false,true,2015-02-27T18:31:29.000Z,true,false,false,,2014-12-17T16:00:00.000Z,0 CVE-2014-1651,https://securityvulnerability.io/vulnerability/CVE-2014-1651,,SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.,Symantec,Web Gateway,,,0.02078000083565712,false,,false,false,false,,,false,false,,2014-06-18T19:00:00.000Z,0 CVE-2013-5017,https://securityvulnerability.io/vulnerability/CVE-2013-5017,,SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors.,Symantec,Web Gateway,9.8,CRITICAL,0.07480999827384949,false,,false,false,false,,,false,false,,2014-06-18T19:00:00.000Z,0 CVE-2014-1650,https://securityvulnerability.io/vulnerability/CVE-2014-1650,,SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.,Symantec,Web Gateway,,,0.00279000005684793,false,,false,false,false,,,false,false,,2014-06-18T19:00:00.000Z,0 CVE-2014-1652,https://securityvulnerability.io/vulnerability/CVE-2014-1652,,Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters.,Symantec,Web Gateway,,,0.26037999987602234,false,,false,false,false,,,false,false,,2014-06-18T19:00:00.000Z,0 CVE-2013-5012,https://securityvulnerability.io/vulnerability/CVE-2013-5012,,Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.,Symantec,Web Gateway,,,0.0007900000200606883,false,,false,false,false,,,false,false,,2014-02-11T02:00:00.000Z,0 CVE-2013-5013,https://securityvulnerability.io/vulnerability/CVE-2013-5013,,Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified other vectors.,Symantec,Web Gateway,,,0.6740000247955322,false,,false,false,false,,,false,false,,2014-02-11T02:00:00.000Z,0 CVE-2013-1616,https://securityvulnerability.io/vulnerability/CVE-2013-1616,,The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script.,Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.023830000311136246,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2013-4673,https://securityvulnerability.io/vulnerability/CVE-2013-4673,,"The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.",Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.017969999462366104,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2013-4670,https://securityvulnerability.io/vulnerability/CVE-2013-4670,,Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.,Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.014170000329613686,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2013-4672,https://securityvulnerability.io/vulnerability/CVE-2013-4672,,"The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass intended access restrictions via a command.",Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.0004299999854993075,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2013-1617,https://securityvulnerability.io/vulnerability/CVE-2013-1617,,Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.,Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.0020099999383091927,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2013-4671,https://securityvulnerability.io/vulnerability/CVE-2013-4671,,Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.,Symantec,"Web Gateway,Web Gateway Appliance 8450,Web Gateway Appliance 8490",,,0.0022100000642240047,false,,false,false,false,,,false,false,,2013-08-01T13:32:00.000Z,0 CVE-2012-4178,https://securityvulnerability.io/vulnerability/CVE-2012-4178,,SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.,Symantec,Web Gateway,,,0.002570000011473894,false,,false,false,false,,,false,false,,2012-08-07T22:00:00.000Z,0 CVE-2012-2953,https://securityvulnerability.io/vulnerability/CVE-2012-2953,,The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.,Symantec,Web Gateway,,,0.9427099823951721,false,,false,false,true,2012-07-26T18:11:05.000Z,true,false,false,,2012-07-23T17:00:00.000Z,0 CVE-2012-2574,https://securityvulnerability.io/vulnerability/CVE-2012-2574,,"SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a ""blind SQL injection"" issue.",Symantec,Web Gateway,,,0.8733000159263611,false,,false,false,false,,,false,false,,2012-07-23T17:00:00.000Z,0