7.2

CVE-2006-3454

Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.

Data is provided by the National Vulnerability Database (NVD)
SymantecClient Security Version1.0
SymantecClient Security Version1.0.1
SymantecClient Security Version1.1
SymantecClient Security Version1.1.1
SymantecClient Security Version2.0
SymantecClient Security Version2.0.1
SymantecClient Security Version2.0.2
SymantecClient Security Version2.0.3
SymantecClient Security Version2.0.4
SymantecClient Security Version3.0
SymantecNorton Antivirus Version8.1 Editioncorporate
SymantecNorton Antivirus Version9.0 Editioncorporate
SymantecNorton Antivirus Version9.0.1 Editioncorporate
SymantecNorton Antivirus Version9.0.2 Editioncorporate
SymantecNorton Antivirus Version10.0 Editioncorporate
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.254
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C