4.9

CVE-2007-1793

Exploit

SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions.  NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.

Data is provided by the National Vulnerability Database (NVD)
SymantecAntivirus Version10.0 Editioncorporate
SymantecAntivirus Version10.0.1 Editioncorporate
SymantecAntivirus Version10.0.1.1 Editioncorporate
SymantecAntivirus Version10.0.2 Editioncorporate
SymantecAntivirus Version10.0.2.1 Editioncorporate
SymantecAntivirus Version10.0.2.2 Editioncorporate
SymantecAntivirus Version10.0.3 Editioncorporate
SymantecAntivirus Version10.0.4 Editioncorporate
SymantecAntivirus Version10.0.5 Editioncorporate
SymantecAntivirus Version10.0.6 Editioncorporate
SymantecAntivirus Version10.0.7 Editioncorporate
SymantecAntivirus Version10.0.8 Editioncorporate
SymantecAntivirus Version10.0.9 Editioncorporate
SymantecClient Security Version3.0
SymantecClient Security Version3.0.0.359
SymantecClient Security Version3.0.1.1000
SymantecClient Security Version3.0.1.1001
SymantecClient Security Version3.0.1.1007
SymantecClient Security Version3.0.1.1008
SymantecClient Security Version3.0.1.1009
SymantecClient Security Version3.0.2
SymantecClient Security Version3.0.2.2000
SymantecClient Security Version3.0.2.2001
SymantecClient Security Version3.0.2.2002
SymantecClient Security Version3.0.2.2010
SymantecClient Security Version3.0.2.2011
SymantecClient Security Version3.0.2.2020
SymantecClient Security Version3.0.2.2021
SymantecClient Security Version3.1
SymantecClient Security Version3.1.0.396
SymantecClient Security Version3.1.0.401
SymantecClient Security Version3.1.394
SymantecClient Security Version3.1.396
SymantecClient Security Version3.1.400
SymantecClient Security Version3.1.401
SymantecNorton 360 Version1.0
SymantecNorton Antispam Version2004
SymantecNorton Antispam Version2005
SymantecNorton Antivirus Version2004
SymantecNorton Antivirus Version2005
SymantecNorton Antivirus Version2006
SymantecNorton Antivirus Version2007
SymantecNorton Antivirus Version2008
SymantecNorton Personal Firewall Version2006_9.1.0.33
SymantecNorton Personal Firewall Version2006_9.1.1.7
SymantecNorton System Works Version2004
SymantecNorton System Works Version2005
SymantecNorton System Works Version2006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.465
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.