Symantec - A Division of Broadcom
Self-Reporting Analysis
Of all the CVEs published by Symantec - A Division of Broadcom as a CNA, 72.3% affect products that Symantec - A Division of Broadcom develops as a vendor.
Of all the CVEs published that affect products developed by Symantec - A Division of Broadcom, 41.8% are self-published by Symantec - A Division of Broadcom as a CNA.
Trends Over Time
The number and severity of CVEs published by Symantec - A Division of Broadcom over time
Top CVEs
All CVEs published by Symantec - A Division of Broadcom as a CNA, regardless of affected vendor or product.
332 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6327HIGH The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execut | Aug 11, 2017 | 8.8 | 88 | YES | YES |
CVE-2017-6326CRITICAL The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotel | Jun 26, 2017 | 10.0 | 86 | NO | YES |
CVE-2013-5014HIGH The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Editi | Feb 14, 2014 | 7.5 | 78 | NO | YES |
CVE-2015-1486HIGH The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action | Aug 1, 2015 | 7.5 | 72 | NO | YES |
CVE-2014-1649HIGH The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS. | May 16, 2014 | 7.9 | 64 | NO | YES |
CVE-2016-5312MEDIUM Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) | Apr 14, 2017 | 6.5 | 62 | NO | YES |
CVE-2014-7285MEDIUM The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into | Dec 17, 2014 | 6.5 | 61 | NO | YES |
CVE-2015-1487MEDIUM The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtai | Aug 1, 2015 | 5.5 | 57 | NO | YES |
CVE-2013-5015MEDIUM SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protect | Feb 14, 2014 | 6.5 | 56 | NO | YES |
CVE-2016-3645CRITICAL Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 | Jun 30, 2016 | 9.8 | 55 | NO | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (332 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Symantec - A Division of Broadcom as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Symantec - A Division of Broadcom as a CNA — matched by CVE ID, not by organization name.