Pcanywhere

Vendor:

First CVE: May 28, 1999 · Active for 27 years

18
Total CVEs
More Total CVEs than 94% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pcanywhere over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 1999
27 years ago
Most Recent CVE
Mar 8, 2012
5,254 days ago

CVE Severity & Scoring

Pcanywhere18 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown18 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown18 (100.0%)
User Interaction
None0 (0.0%)
Unknown18 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown18 (100.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filte
Jan 25, 201210.063NOYES
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.
Apr 6, 200010.039NOYES
Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vec
Dec 1, 20057.835NOYES
Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable permissions for product-installati
Jan 25, 20126.831NOYES
Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (
Feb 6, 201210.030NONO
The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite p
Mar 8, 20125.029NOYES
pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.
Apr 25, 20005.025NOYES
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
May 28, 19995.023NOYES
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec
Sep 19, 20064.922NOYES
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties
Jun 16, 20057.220NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
44.4% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Pcanywhere

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.247.54.1%02
9.0.127.54.9%01
9.057.04.2%03
8.0.236.74.5%02
8.0.136.74.5%02
8.036.72.5%01
5.0110.02.7%00
12.6.758038.914.3%02
12.6.6538.716.7%02
12.5.53957.410.5%03
12.5.325.04.8%01
12.5.26536.74.1%01
12.587.58.8%03
12.146.23.2%01
12.0.325.04.8%01
12.0.225.04.8%01
12.0.125.04.8%01
12.044.82.6%01
11.5.166.23.8%02
11.576.03.4%03