4.3
CVE-2009-1428
- EPSS 2.33%
- Veröffentlicht 29.04.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:15
- Erkennungen
Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Endpoint Protection Version 11.0
Symantec ≫ Norton 360 Version 1.0
Symantec ≫ Norton Internet Security Version 2005 Edition anti_spyware
Symantec ≫ Norton Internet Security Version 2005 Edition professional
Symantec ≫ Norton Internet Security Version 2005 Update 11.0
Symantec ≫ Norton Internet Security Version 2005 Update 11.0.9
Symantec ≫ Norton Internet Security Version 2005 Update 11.5.6.14
Symantec ≫ Norton Internet Security Version 2005_contains_nav_11.0.0
Symantec ≫ Norton Internet Security Version 2006
Symantec ≫ Norton Internet Security Version 2006 Edition professional
Symantec ≫ Norton Internet Security Version 2007
Symantec ≫ Norton Internet Security Version 2008
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.33% | 0.813 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://osvdb.org/54132
http://secunia.com/advisories/34936
http://www.securityfocus.com/bid/34669
http://www.securitytracker.com/id?1022133
http://www.securitytracker.com/id?1022134
http://www.securitytracker.com/id?1022135
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_01
http://www.vupen.com/english/advisories/2009/1203
https://exchange.xforce.ibmcloud.com/vulnerabilities/50170