Symantec, a division of Broadcom, maintains a broad portfolio of endpoint security, antivirus, and web-gateway products that are widely deployed across enterprise and consumer environments, representing a substantial attack surface. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and value of security products as targets for adversaries seeking to bypass or disable protections. Vulnerabilities affecting this vendor recur across flagship products such as Endpoint Protection, Norton AntiVirus, and Endpoint Protection Manager through weakness classes including cross-site scripting, memory-buffer handling flaws, and input-validation issues that are characteristic of large, feature-rich security suites. Defenders should treat updates to these products as priority maintenance, as compromise of endpoint or gateway security software can undermine the entire defense posture of an organization. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Symantec - A Division of Broadcom over time
Of all the CVEs published by Symantec - A Division of Broadcom as a CNA, 72.3% affect products that Symantec - A Division of Broadcom develops as a vendor.
Of all the CVEs published that affect products developed by Symantec - A Division of Broadcom, 41.8% are self-published by Symantec - A Division of Broadcom as a CNA.
Signals from CVEs in this vendor scope (574 CVEs).
574 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1429HIGH The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Centr | Apr 29, 2009 | 10.0 | 89 | NO | YES |
CVE-2017-6327HIGH The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execut | Aug 11, 2017 | 8.8 | 88 | YES | YES |
CVE-2017-6326CRITICAL The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotel | Jun 26, 2017 | 10.0 | 86 | NO | YES |
CVE-2012-2953HIGH The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts. | Jul 23, 2012 | 10.0 | 83 | NO | YES |
CVE-2012-0297HIGH The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by ( | May 21, 2012 | 10.0 | 83 | NO | YES |
CVE-2012-0299HIGH The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly | May 21, 2012 | 10.0 | 81 | NO | YES |
CVE-2006-2630HIGH Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors. | May 27, 2006 | 10.0 | 81 | NO | YES |
CVE-2013-5014HIGH The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Editi | Feb 14, 2014 | 7.5 | 78 | NO | YES |
CVE-2004-0363HIGH Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execu | Apr 15, 2004 | 7.5 | 78 | NO | YES |
CVE-2007-1689HIGH Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code | May 16, 2007 | 10.0 | 77 | NO | YES |
Signals from CVEs in this vendor scope (574 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Symantec - A Division of Broadcom.
Media articles that mention a CVE ID that affects a product developed by Symantec - A Division of Broadcom — matched by CVE ID, not by vendor name.