Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Symantec - A Division of Broadcom

First CVE: May 4, 1997Active for: 29 yearsTotal CVEs: 574
54.9
VTI Score
TOP TARGET

Symantec, a division of Broadcom, maintains a broad portfolio of endpoint security, antivirus, and web-gateway products that are widely deployed across enterprise and consumer environments, representing a substantial attack surface. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and value of security products as targets for adversaries seeking to bypass or disable protections. Vulnerabilities affecting this vendor recur across flagship products such as Endpoint Protection, Norton AntiVirus, and Endpoint Protection Manager through weakness classes including cross-site scripting, memory-buffer handling flaws, and input-validation issues that are characteristic of large, feature-rich security suites. Defenders should treat updates to these products as priority maintenance, as compromise of endpoint or gateway security software can undermine the entire defense posture of an organization. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
574
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Symantec - A Division of Broadcom over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 1997
29 years ago
Most Recent CVE
Jan 26, 2024
910 days ago

Self-Reporting Analysis

Of all the CVEs published by Symantec - A Division of Broadcom as a CNA, 72.3% affect products that Symantec - A Division of Broadcom develops as a vendor.

72.3%
27.7%
Self-reported: 240 (72.3%)
Third-party: 92 (27.7%)

Of all the CVEs published that affect products developed by Symantec - A Division of Broadcom, 41.8% are self-published by Symantec - A Division of Broadcom as a CNA.

41.8%
58.2%
Self-published: 240 (41.8%)
Other CNAs: 334 (58.2%)

Products(247 total)

Top CVEs

Signals from CVEs in this vendor scope (574 CVEs).

574 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-1429HIGH
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Centr
Apr 29, 200910.089NOYES
CVE-2017-6327HIGH
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execut
Aug 11, 20178.888YESYES
CVE-2017-6326CRITICAL
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotel
Jun 26, 201710.086NOYES
CVE-2012-2953HIGH
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
Jul 23, 201210.083NOYES
CVE-2012-0297HIGH
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (
May 21, 201210.083NOYES
CVE-2012-0299HIGH
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly
May 21, 201210.081NOYES
CVE-2006-2630HIGH
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
May 27, 200610.081NOYES
CVE-2013-5014HIGH
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Editi
Feb 14, 20147.578NOYES
CVE-2004-0363HIGH
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execu
Apr 15, 20047.578NOYES
CVE-2007-1689HIGH
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code
May 16, 200710.077NOYES
View all 574 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products574 CVEs
45%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local73 (12.7%)
Network72 (12.5%)
Unknown402 (70.0%)
Physical9 (1.6%)
Adjacent Network18 (3.1%)
Attack Complexity
Low158 (27.5%)
High14 (2.4%)
Unknown402 (70.0%)
User Interaction
None130 (22.6%)
Unknown402 (70.0%)
Required42 (7.3%)
Privileges Required
Low83 (14.5%)
High25 (4.4%)
None64 (11.1%)
Unknown402 (70.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (574 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 99th percentile
Metasploit
26 CVEs
4.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
108 CVEs
18.8% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Symantec - A Division of Broadcom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Symantec - A Division of Broadcom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Symantec - A Division of Broadcom's Products

View all 4 CNAs →

Top CWEs