9.3
CVE-2010-0107
- EPSS 6.53%
- Veröffentlicht 23.02.2010 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:15:29
- Erkennungen
Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Client Security Version 3.0
Symantec ≫ Client Security Version 3.0.1.1000
Symantec ≫ Client Security Version 3.0.1.1001
Symantec ≫ Client Security Version 3.0.1.1007
Symantec ≫ Client Security Version 3.0.1.1008
Symantec ≫ Client Security Version 3.0.1.1009
Symantec ≫ Client Security Version 3.0.2
Symantec ≫ Client Security Version 3.0.2.2000
Symantec ≫ Client Security Version 3.0.2.2001
Symantec ≫ Client Security Version 3.0.2.2002
Symantec ≫ Client Security Version 3.0.2.2010
Symantec ≫ Client Security Version 3.0.2.2011
Symantec ≫ Client Security Version 3.0.2.2020
Symantec ≫ Client Security Version 3.0.2.2021
Symantec ≫ Client Security Version 3.1
Symantec ≫ Client Security Version 3.1 Update mr4
Symantec ≫ Client Security Version 3.1 Update mr5
Symantec ≫ Client Security Version 3.1 Update mr6
Symantec ≫ Client Security Version 3.1.0.396
Symantec ≫ Client Security Version 3.1.0.401
Symantec ≫ Client Security Version 3.1.396
Symantec ≫ Client Security Version 3.1.400
Symantec ≫ Client Security Version 3.1.401
Symantec ≫ Norton 360 Version 1.0
Symantec ≫ Norton 360 Version 2.0
Symantec ≫ Norton Antivirus Version 2006
Symantec ≫ Norton Antivirus Version 2007
Symantec ≫ Norton Antivirus Version 2008
Symantec ≫ Norton Internet Security Version 2006
Symantec ≫ Norton Internet Security Version 2007
Symantec ≫ Norton Internet Security Version 2008
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.53% | 0.929 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://osvdb.org/62412
http://secunia.com/advisories/38654
http://www.securityfocus.com/archive/1/509717/100/0/threaded
http://www.securityfocus.com/bid/38217
http://www.securitytracker.com/id?1023628
http://www.securitytracker.com/id?1023629
http://www.securitytracker.com/id?1023630
http://www.securitytracker.com/id?1023631
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_01
http://www.vupen.com/english/advisories/2010/0411
https://exchange.xforce.ibmcloud.com/vulnerabilities/56357