VendorsSymantecantivirus_scan_engine5.0.0.24
Vulnerabilities

Symantec Antivirus Scan Engine 5.0.0.24

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-0230
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.
Published 2006-04-25 · Modified
10.01 PoCEPSS 0.161
CVE-2006-0231
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.
Published 2006-04-25 · Modified
6.4EPSS 0.019
CVE-2006-0232
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
Published 2006-04-25 · Modified
5.0EPSS 0.024