5

CVE-2012-0291

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote attackers to cause a denial of service (application crash or hang) via (1) malformed data from a client, (2) malformed data from a server, or (3) an invalid response.

Data is provided by the National Vulnerability Database (NVD)
SymantecPcanywhere Updatesp3 Version <= 12.5
SymantecPcanywhere Version10.0
SymantecPcanywhere Version10.5
SymantecPcanywhere Version11.0
SymantecPcanywhere Version11.0.1
SymantecPcanywhere Version11.5
SymantecPcanywhere Version11.5.1
SymantecPcanywhere Version12.0
SymantecPcanywhere Version12.0.1
SymantecPcanywhere Version12.0.2
SymantecPcanywhere Version12.0.3
SymantecPcanywhere Version12.1
SymantecPcanywhere Version12.5
SymantecPcanywhere Version12.5 Updatesp1
SymantecPcanywhere Version12.5 Updatesp2
SymantecPcanywhere Version12.5.3
SymantecPcanywhere Version12.5.265
SymantecPcanywhere Version12.5.539
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.67% 0.688
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.