10

CVE-2010-0108

Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Antivirus Version 10.0
Symantec ≫ Antivirus Version 10.0.1
Symantec ≫ Antivirus Version 10.0.1.1
Symantec ≫ Antivirus Version 10.0.2
Symantec ≫ Antivirus Version 10.0.2.1
Symantec ≫ Antivirus Version 10.0.2.2
Symantec ≫ Antivirus Version 10.0.3
Symantec ≫ Antivirus Version 10.0.4
Symantec ≫ Antivirus Version 10.0.5
Symantec ≫ Antivirus Version 10.0.6
Symantec ≫ Antivirus Version 10.0.7
Symantec ≫ Antivirus Version 10.0.8
Symantec ≫ Antivirus Version 10.0.9
Symantec ≫ Antivirus Version 10.1
Symantec ≫ Antivirus Version 10.1 Edition corporate
Symantec ≫ Antivirus Version 10.1 Update mp1 Edition corporate
Symantec ≫ Antivirus Version 10.1 Update mr4 Edition corporate
Symantec ≫ Antivirus Version 10.1 Update mr5 Edition corporate
Symantec ≫ Antivirus Version 10.1 Update mr7 Edition corporate
Symantec ≫ Antivirus Version 10.1.0.1 Edition corporate
Symantec ≫ Antivirus Version 10.1.4 Edition corporate
Symantec ≫ Antivirus Version 10.1.4.1 Edition corporate
Symantec ≫ Antivirus Version 10.1.5 Edition corporate
Symantec ≫ Antivirus Version 10.1.5.1 Edition corporate
Symantec ≫ Antivirus Version 10.1.6 Edition corporate
Symantec ≫ Antivirus Version 10.1.6.1 Edition corporate
Symantec ≫ Antivirus Version 10.1.7 Edition corporate
Symantec ≫ Antivirus Version 10.2 Edition corporate
Symantec ≫ Antivirus Version 10.2 Update mr2 Edition corporate
Symantec ≫ Antivirus Version 10.2 Update mr3 Edition corporate
Symantec ≫ Client Security Version 3.0
Symantec ≫ Client Security Version 3.0 Update mr1
Symantec ≫ Client Security Version 3.0 Update mr2
Symantec ≫ Client Security Version 3.0.0.359
Symantec ≫ Client Security Version 3.0.1.1000
Symantec ≫ Client Security Version 3.0.1.1007
Symantec ≫ Client Security Version 3.0.1.1008
Symantec ≫ Client Security Version 3.0.2
Symantec ≫ Client Security Version 3.0.2.2000
Symantec ≫ Client Security Version 3.0.2.2001
Symantec ≫ Client Security Version 3.0.2.2010
Symantec ≫ Client Security Version 3.0.2.2011
Symantec ≫ Client Security Version 3.0.2.2020
Symantec ≫ Client Security Version 3.0.2.2021
Symantec ≫ Client Security Version 3.1
Symantec ≫ Client Security Version 3.1 Update mr4
Symantec ≫ Client Security Version 3.1 Update mr5
Symantec ≫ Client Security Version 3.1 Update mr7
Symantec ≫ Client Security Version 3.1.0.396
Symantec ≫ Client Security Version 3.1.0.401
Symantec ≫ Client Security Version 3.1.394
Symantec ≫ Client Security Version 3.1.400
Symantec ≫ Client Security Version 3.1.401
Symantec ≫ Endpoint Protection Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.41% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://dsecrg.com/pages/vul/show.php?id=139
http://secunia.com/advisories/38651
Vendor Advisory
http://www.securityfocus.com/archive/1/509681/100/0/threaded
http://www.securityfocus.com/bid/38222
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_02
http://www.vupen.com/english/advisories/2010/0412
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/56355