9.3
CVE-2010-0107
- EPSS 27.11%
- Published 23.02.2010 20:30:00
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
Data is provided by the National Vulnerability Database (NVD)
Symantec ≫ Client Security Version3.0
Symantec ≫ Client Security Version3.0.1.1000
Symantec ≫ Client Security Version3.0.1.1001
Symantec ≫ Client Security Version3.0.1.1007
Symantec ≫ Client Security Version3.0.1.1008
Symantec ≫ Client Security Version3.0.1.1009
Symantec ≫ Client Security Version3.0.2
Symantec ≫ Client Security Version3.0.2.2000
Symantec ≫ Client Security Version3.0.2.2001
Symantec ≫ Client Security Version3.0.2.2002
Symantec ≫ Client Security Version3.0.2.2010
Symantec ≫ Client Security Version3.0.2.2011
Symantec ≫ Client Security Version3.0.2.2020
Symantec ≫ Client Security Version3.0.2.2021
Symantec ≫ Client Security Version3.1
Symantec ≫ Client Security Version3.1 Updatemr4
Symantec ≫ Client Security Version3.1 Updatemr5
Symantec ≫ Client Security Version3.1 Updatemr6
Symantec ≫ Client Security Version3.1.0.396
Symantec ≫ Client Security Version3.1.0.401
Symantec ≫ Client Security Version3.1.396
Symantec ≫ Client Security Version3.1.400
Symantec ≫ Client Security Version3.1.401
Symantec ≫ Norton 360 Version1.0
Symantec ≫ Norton 360 Version2.0
Symantec ≫ Norton Antivirus Version2006
Symantec ≫ Norton Antivirus Version2007
Symantec ≫ Norton Antivirus Version2008
Symantec ≫ Norton Internet Security Version2006
Symantec ≫ Norton Internet Security Version2007
Symantec ≫ Norton Internet Security Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 27.11% | 0.959 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.