Norton's vulnerability profile concentrates in a modest set of consumer security and system-utility products, including its password manager, system optimization tools, and security installation utilities. The recurring weakness classes span certificate and origin validation issues, code injection, and privilege management flaws that reflect the trust and code-execution boundaries inherent to security software and administrative tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Norton over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4294HIGH Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromis | Jan 10, 2023 | 7.8 | 25 | NO | NO |
CVE-2019-19548HIGH Norton Power Eraser, prior to 5.3.0.67, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the softw | Jan 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2017-13676HIGH Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker pr | Sep 28, 2017 | 7.0 | 22 | NO | NO |
CVE-2019-19546MEDIUM Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of i | Dec 5, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-19545MEDIUM Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on | Dec 5, 2019 | 6.3 | 20 | NO | NO |
CVE-2019-18381MEDIUM Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on | Dec 5, 2019 | 6.3 | 20 | NO | NO |
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certi | Nov 22, 2017 | 3.7 | 17 | NO | NO |
Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order | Jul 16, 2019 | 3.9 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Norton.
Media articles that mention a CVE ID that affects a product developed by Norton — matched by CVE ID, not by vendor name.