CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “symantec”

158 vulnerabilities found for “symantec”

Page 1 of 8

CVE-2025-8660
CRITICAL9.8

Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

broadcom / symantec_pgp_encryption
Network
Published Aug 11, 2025
Page 1 of 8
CVE-2025-8661
MEDIUM6.1

A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.

broadcom / symantec_pgp_encryption
Network
Published Aug 11, 2025
CVE-2024-23617
CRITICAL9.6

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution.

broadcom / symantec_data_center_security_server
Network
Published Jan 26, 2024
CVE-2024-23616
CRITICAL10.0

A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

broadcom / symantec_server_management_suite
Network
Published Jan 26, 2024
CVE-2023-23950
MEDIUM6.1

User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.

broadcom / symantec_identity_governance_and_administration+4
Network
Published Jan 26, 2023
CVE-2023-23949
MEDIUM5.4

An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.

broadcom / symantec_identity_governance_and_administration+4
Network
Published Jan 26, 2023
CVE-2023-23951
MEDIUM6.1

Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application

broadcom / symantec_identity_governance_and_administration+4
Network
Published Jan 26, 2023
CVE-2021-30648
CRITICAL9.8

The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

broadcom / symantec_proxysg+32
Network
Published Jun 30, 2021
CVE-2020-5832
HIGH7.8

Symantec Data Center Security Manager Component, prior to 6.8.2 (aka 6.8 MP2), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

symantec / data_center_security
Local
Published Apr 6, 2020
CVE-2016-5311
HIGH7.8

A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malicious user obtain system privileges.

symantec / endpoint_protection+8
Local
Published Jan 9, 2020
CVE-2016-6593
HIGH7.8

A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.

symantec / vip_access_desktop
Local
Published Jan 8, 2020
CVE-2016-6589
MEDIUM6.5

A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.

symantec / it_management_suite
Network
Published Jan 8, 2020
CVE-2016-6590
HIGH7.8

A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.

symantec / encryption_desktop+8
Local
Published Jan 8, 2020
CVE-2016-6588
MEDIUM5.4

A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.

symantec / it_management_suite
Network
Published Jan 8, 2020
CVE-2018-18369
HIGH7.8

Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.

symantec / endpoint_protection+4
Local
Published Apr 25, 2019
CVE-2018-18366
MEDIUM6.5

Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.

symantec / endpoint_protection+52
Local
Published Apr 25, 2019
CVE-2018-12238
HIGH7.8

Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a type of exploit that works to circumvent one of the virus detection engines to avoid a specific type of virus protection. One of the antivirus engines depends on a signature pattern from a database to identify malicious files and viruses; the antivirus bypass exploit looks to alter the file being scanned so it is not detected.

symantec / endpoint_protection+3
Local
Published Nov 29, 2018
CVE-2018-12239
MEDIUM6.8

Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a type of exploit that works to circumvent one of the virus detection engines to avoid a specific type of virus protection. One of the antivirus engines depends on a signature pattern from a database to identify malicious files and viruses; the antivirus bypass exploit looks to alter the file being scanned so it is not detected.

symantec / endpoint_protection+3
Physical
Published Nov 29, 2018
CVE-2018-12246
MEDIUM6.1

Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code into the website's rendered copy running inside the end user's web browser. It does not allow injecting code into the real (isolated) copy of the website running on the WI Threat Isolation Engine.

symantec / web_isolation
Network
Published Oct 22, 2018
CVE-2018-5238
HIGH7.8

Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application.

symantec / norton_power_eraser+1
Local
Published Aug 22, 2018