7.2

CVE-2012-0289

Exploit

Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecEndpoint Protection Version11.0.6000
SymantecEndpoint Protection Version11.0.6100
SymantecEndpoint Protection Version11.0.6200
SymantecEndpoint Protection Version11.0.6200.754
SymantecEndpoint Protection Version11.0.6300
SymantecEndpoint Protection Version11.0.7000
SymantecEndpoint Protection Version11.0.7100
SymantecNetwork Access Control Version11.0.6000
SymantecNetwork Access Control Version11.0.6100
SymantecNetwork Access Control Version11.0.6200
SymantecNetwork Access Control Version11.0.6300
SymantecNetwork Access Control Version11.0.7000
SymantecNetwork Access Control Version11.0.7100
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.607
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.