9.3

CVE-2010-0107

Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.  NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."

Data is provided by the National Vulnerability Database (NVD)
SymantecClient Security Version3.0
SymantecClient Security Version3.0.1.1000
SymantecClient Security Version3.0.1.1001
SymantecClient Security Version3.0.1.1007
SymantecClient Security Version3.0.1.1008
SymantecClient Security Version3.0.1.1009
SymantecClient Security Version3.0.2
SymantecClient Security Version3.0.2.2000
SymantecClient Security Version3.0.2.2001
SymantecClient Security Version3.0.2.2002
SymantecClient Security Version3.0.2.2010
SymantecClient Security Version3.0.2.2011
SymantecClient Security Version3.0.2.2020
SymantecClient Security Version3.0.2.2021
SymantecClient Security Version3.1
SymantecClient Security Version3.1 Updatemr4
SymantecClient Security Version3.1 Updatemr5
SymantecClient Security Version3.1 Updatemr6
SymantecClient Security Version3.1.0.396
SymantecClient Security Version3.1.0.401
SymantecClient Security Version3.1.396
SymantecClient Security Version3.1.400
SymantecClient Security Version3.1.401
SymantecNorton 360 Version1.0
SymantecNorton 360 Version2.0
SymantecNorton Antivirus Version2006
SymantecNorton Antivirus Version2007
SymantecNorton Antivirus Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 27.11% 0.959
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.