Symantec
Symantec Messaging Gateway: vulnerabilidades y CVE
Symantec Messaging Gateway tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-25630 | Media (5.4) | 1.5% | — | 9 dic 2022 | An authenticated user can embed malicious content with XSS into the admin group policy page. |
| CVE-2022-25629 | Media (5.4) | 0.39% | — | 9 dic 2022 | An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column). |
| CVE-2012-6277 | Alta (7.8) | 8.1% | — | 21 feb 2020 | Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging… |
| CVE-2019-18379 | Alta (7.3) | 1.1% | — | 11 dic 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a… |
| CVE-2019-18378 | Media (4.8) | 0.73% | — | 11 dic 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other… |
| CVE-2019-18377 | Alta (7.2) | 1.4% | — | 11 dic 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated… |
| CVE-2019-9699 | Media (4.5) | 0.48% | — | 24 oct 2019 | Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data. |
| CVE-2018-12243 | Alta (8.8) | 0.77% | — | 19 sept 2018 | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a… |
| CVE-2018-12242 | Crítica (9.8) | 3.0% | — | 19 sept 2018 | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in… |
| CVE-2017-15532 | Media (5.7) | 1.4% | — | 20 dic 2017 | Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web… |
| CVE-2017-6326 | Crítica (10) | 73% | — | 26 jun 2017 | The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target… |
| CVE-2017-6325 | Media (6.6) | 2.5% | — | 26 jun 2017 | The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is… |
| CVE-2017-6324 | Alta (7.3) | 1.3% | — | 26 jun 2017 | The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm'… |
| CVE-2016-5312 | Media (6.5) | 54% | — | 14 abr 2017 | Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to… |
| CVE-2016-5310 | Media (5.5) | 5.3% | — | 14 abr 2017 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection… |
| CVE-2016-5309 | Media (5.5) | 6.9% | — | 14 abr 2017 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection… |
| CVE-2016-2204 | Alta (8.2) | 0.67% | — | 22 abr 2016 | The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input. |
| CVE-2016-2203 | Alta (7.8) | 7.1% | — | 22 abr 2016 | The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges. |
| CVE-2014-1648 | Media (4.3) | 2.1% | — | 23 abr 2014 | Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary… |
| CVE-2012-4347 | Media (5) | 59% | — | 5 dic 2012 | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter… |
| CVE-2012-3581 | Baja (3.3) | 0.64% | — | 29 ago 2012 | Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to obtain potentially sensitive information about component versions via unspecified vectors. |
| CVE-2012-3580 | Alta (7.7) | 1.1% | — | 29 ago 2012 | Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface. |
| CVE-2012-3579 | Alta (7.9) | 40% | — | 29 ago 2012 | Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session. |
| CVE-2012-0308 | Media (6.8) | 1.9% | — | 29 ago 2012 | Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators. |
| CVE-2012-0307 | Media (4.3) | 2.0% | — | 29 ago 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content. |