Symantec - A Division of Broadcom

First CVE: Feb 18, 2013Active for: 13 years
332
CVEs Published
More CVEs Published than 84% of tracked CNAs
23.7
Avg CVEs / Year
More Avg CVEs / Year than 72% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 82% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Symantec - A Division of Broadcom as a CNA, 72.3% affect products that Symantec - A Division of Broadcom develops as a vendor.

72.3%
27.7%
Self-reported: 240Third-party: 92

Of all the CVEs published that affect products developed by Symantec - A Division of Broadcom, 41.8% are self-published by Symantec - A Division of Broadcom as a CNA.

41.8%
58.2%
Self-published: 240Published by other CNAs: 334

Trends Over Time

The number and severity of CVEs published by Symantec - A Division of Broadcom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2013
13 years ago
Most Recent CVE
Jul 17, 2026
8 days ago

Top CVEs

All CVEs published by Symantec - A Division of Broadcom as a CNA, regardless of affected vendor or product.

332 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execut
Aug 11, 20178.888YESYES
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotel
Jun 26, 201710.086NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Editi
Feb 14, 20147.578NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action
Aug 1, 20157.572NOYES
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
May 16, 20147.964NOYES
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot)
Apr 14, 20176.562NOYES
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into
Dec 17, 20146.561NOYES
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtai
Aug 1, 20155.557NOYES
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protect
Feb 14, 20146.556NOYES
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6
Jun 30, 20169.855NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA332 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local85 (25.6%)
Network120 (36.1%)
Unknown82 (24.7%)
Physical10 (3.0%)
Adjacent Network19 (5.7%)
Attack Complexity
Low223 (67.2%)
High27 (8.1%)
Unknown82 (24.7%)
User Interaction
None188 (56.6%)
Unknown82 (24.7%)
Required56 (16.9%)
Privileges Required
Low109 (32.8%)
High41 (12.3%)
None100 (30.1%)
Unknown82 (24.7%)

Exploit Exposure

Signals from CVEs in this cna scope (332 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 82nd percentile
Metasploit
9 CVEs
2.7% of CVEs· 94th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
45 CVEs
13.6% of CVEs· 99th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Symantec - A Division of Broadcom as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Symantec - A Division of Broadcom as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs