← Vulnerability feed

Vulnerability record · CVE-2009-1432 · published 30 April 2009

CVE-2009-1432: Symantec antivirus improper input validation vulnerability

Symantec · Antivirus

Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.

5.0 CVSS 2.0 Medium EPSS 4.2% · top 9.3% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
4.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/34856 Third Party Advisory
http://secunia.com/advisories/34935 Third Party Advisory
http://securitytracker.com/id?1022136 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1022137 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1022138 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/34668 Third Party AdvisoryVDB Entry
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1202 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1204 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 Third Party AdvisoryVDB Entry
http://secunia.com/advisories/34856 Third Party Advisory
http://secunia.com/advisories/34935 Third Party Advisory
http://securitytracker.com/id?1022136 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1022137 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1022138 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/34668 Third Party AdvisoryVDB Entry
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1202 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1204 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 Third Party AdvisoryVDB Entry

Track CVE-2009-1432 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0108Symantec antivirus memory buffer overflow vulnerabilityBuffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9…EPSS 19%10.0CVE-2009-1429Symantec AMS2 Intel LANDesk CBA Remote Command ExecutionThe Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2) passes crafted packet contents directly to the CreateProcessA …EPSS 88%analysed10.0CVE-2006-2630Symantec Antivirus and Client Security stack buffer overflowSymantec Antivirus 10.1 and Client Security 3.1 contain a stack-based buffer overflow that remote attackers can trigger through unspecified attack ve…EPSS 74%analysed10.0CVE-2004-0444Symantec client firewall vulnerabilityMultiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 throug…EPSS 13%9.8CVE-2016-3645Symantec norton security vulnerabilityInteger overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…EPSS 25%9.3CVE-2012-4953Symantec antivirus memory buffer overflow vulnerabilityThe decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corpor…EPSS 6.0%9.3CVE-2012-0295Symantec endpoint protection code injection vulnerabilityThe Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…EPSS 4.0%9.3CVE-2011-0688Symantec antivirus improper authentication vulnerabilityIntel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2009-1432), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.