Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.5%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg29/5/201817/6/2026
Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When parsing SAML responses, ASG and ProxySG…
ModificadaMedia (5.9)1.6%—Broadcom Symantec Intelligencecenter17/5/201817/6/2026
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the session keys required to decrypt the…
ModificadaAlta (8)15%💥 ExploitSymantec Norton Core Firmware30/4/201817/6/2026
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arbitrary commands on the host system via vulnerable software.
ModificadaAlta (8)0.49%—Symantec Management Console16/4/201817/6/2026
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request…
ModificadaAlta (7.8)1.3%—Symantec Endpoint Protection16/4/201817/6/2026
Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential exists for file metadata to be interpreted…
ModificadaAlta (7)0.38%—Symantec Endpoint Protection16/4/201817/6/2026
A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin user would need to be able to save an executable file to disk and then be able to successfully run…
ModificadaMedia (4.8)1.0%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg11/4/201817/6/2026
Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.
ModificadaAlta (7.5)5.0%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg11/4/201817/6/2026
Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes.
ModificadaMedia (6.8)4.8%💥 ExploitBroadcom Advanced Secure GatewayBroadcom Symantec Proxysg11/4/201817/6/2026
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
ModificadaMedia (6.7)0.40%—Symantec Norton APP Lock26/3/201817/6/2026
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.
ModificadaMedia (5.5)0.62%—Symantec Backup Exec System RecoverySymantec Norton 360Symantec Norton GhostSymantec System Recovery 201119/2/201816/6/2026
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.
ModificadaMedia (6.5)0.84%—Symantec Altiris Deployment Solution19/2/201816/6/2026
DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of service via a crafted request.
ModificadaCrítica (9.8)2.4%—Symantec Reporter23/1/201817/6/2026
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.
ModificadaAlta (8.3)3.3%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+2018/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaAlta (7.5)0.49%—Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+1618/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks…
ModificadaMedia (4.7)2.5%—Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+1618/1/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaMedia (6.1)1.5%—Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg10/1/201817/6/2026
The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject…
ModificadaMedia (6.1)1.5%—Broadcom Symantec Proxysg10/1/201817/6/2026
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This…
ModificadaMedia (5.7)1.4%—Symantec Messaging Gateway20/12/201717/6/2026
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to access arbitrary files and directories…
ModificadaBaja (3.3)0.34%—Symantec Norton Family13/12/201717/6/2026
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to an Information Disclosure issue. Information disclosure is a very common issue that attackers will attempt to exploit as a first pass across the application. As they probe the application they will take note of anything that may seem out of place…
ModificadaMedia (6.2)0.36%—Symantec Norton Family13/12/201717/6/2026
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to a Denial of Service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular device unavailable to its intended user by temporarily or indefinitely disrupting services of a specific host within a network.
ModificadaMedia (6.8)1.1%—Symantec Management Console20/11/201717/6/2026
Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are…
ModificadaMedia (6.8)0.33%—Symantec Endpoint Encryption13/11/201717/6/2026
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a null pointer de-reference issue, which can result in a NullPointerException that can lead to a privilege escalation scenario.
ModificadaMedia (4.5)0.27%—Symantec Endpoint Encryption13/11/201717/6/2026
Prior to SEE v11.1.3MP1, Symantec Endpoint Encryption can be susceptible to a denial of service (DoS) attack, which is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific…
ModificadaAlta (7.1)1.7%💥 ExploitSymantec Endpoint Protection6/11/201717/6/2026
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.
Orbitaley — Vulnerabilidades