Network Associates developed a range of security and networking infrastructure products including PKI servers, email filtering appliances, network sniffers, and firewalls that were deployed across enterprise environments, though many products have reached end-of-life. The vendor's vulnerability disclosures span a focused product portfolio yet are widely represented in historical security catalogs, reflecting the broad deployment and extended support lifecycles of these legacy systems. Its recurring weaknesses cluster around memory-safety issues and buffer-boundary violations, characteristic of security infrastructure built during eras with fewer compiler-level protections, alongside a tendency for public exploit tooling to become available for disclosed flaws. Defenders should approach legacy Network Associates products as end-of-life systems: prioritize inventory and isolation of still-deployed instances rather than relying on vendor patching, and treat any exposed deployment as a remediation candidate. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Network Associates over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0437HIGH Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands. | May 18, 2000 | 10.0 | 37 | NO | YES |
CVE-2000-0741HIGH Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with | Oct 20, 2000 | 7.5 | 30 | NO | YES |
CVE-2000-1157HIGH Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name. | Jan 9, 2001 | 10.0 | 25 | NO | NO |
CVE-2000-0740MEDIUM Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port. | Oct 20, 2000 | 5.0 | 24 | NO | YES |
CVE-2000-1129MEDIUM McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. | Jan 9, 2001 | 5.0 | 23 | NO | YES |
CVE-2000-0739MEDIUM Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in | Oct 20, 2000 | 5.0 | 23 | NO | YES |
CVE-1999-0683MEDIUM Denial of service in Gauntlet Firewall via a malformed ICMP packet. | Jul 30, 1999 | 5.0 | 23 | NO | YES |
CVE-2002-1121HIGH SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefan | Sep 24, 2002 | 7.5 | 21 | NO | NO |
CVE-2001-1456HIGH Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | Sep 4, 2001 | 7.5 | 21 | NO | NO |
CVE-2000-1158HIGH NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords. | Jan 9, 2001 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Network Associates.
Media articles that mention a CVE ID that affects a product developed by Network Associates — matched by CVE ID, not by vendor name.