Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Symantec Veritas

First CVE: Jun 16, 2000Active for: 26 yearsTotal CVEs: 27
53.3
VTI Score
TOP TARGET

Symantec Veritas maintains a focused portfolio of enterprise backup, recovery, and cluster-management products such as Backup Exec, NetBackup, and Cluster Server that protect critical infrastructure and data across on-premises and hybrid environments. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability, reflecting the high-value target these data-protection platforms represent to attackers seeking to disrupt recovery operations or exfiltrate protected data. Recurring weakness patterns center on improper input validation in management interfaces and configuration systems, a structural risk inherent to complex administrative applications. Defenders should prioritize patches for internet-facing backup and recovery instances and audit administrative access paths; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Symantec Veritas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2000
26 years ago
Most Recent CVE
Feb 21, 2008
6,732 days ago

Products(19 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-2611HIGH
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static p
Aug 17, 200510.087NOYES
CVE-2004-1172HIGH
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitr
Jan 10, 200510.087NOYES
CVE-2005-0773HIGH
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary
Jun 18, 20057.581NOYES
CVE-2005-2715HIGH
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/
Oct 12, 200510.070NOYES
CVE-2005-0771HIGH
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP
Jun 23, 200510.067NOYES
CVE-2005-3116HIGH
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote at
Nov 18, 200510.050NOYES
CVE-2002-1374HIGH
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, w
Dec 23, 20027.545NOYES
CVE-2002-1375HIGH
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
Dec 23, 20027.542NOYES
CVE-2000-0494HIGH
Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server scrip
Jun 16, 20007.229NOYES
CVE-2002-1376HIGH
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routi
Dec 23, 20027.527NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
30%
67%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown27 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown27 (100.0%)
User Interaction
None0 (0.0%)
Unknown27 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown27 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
14.8% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Symantec Veritas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Symantec Veritas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Symantec Veritas's Products

View all 1 CNAs →

Top CWEs