Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://layereddefense.com/SAV13SEPT.html - | |
References | () http://secunia.com/advisories/21884 - | |
References | () http://securityresponse.symantec.com/avcenter/security/Content/2006.09.13.html - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1016842 - | |
References | () http://www.securityfocus.com/archive/1/446041/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/446293/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/19986 - | |
References | () http://www.vupen.com/english/advisories/2006/3599 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28936 - |
Information
Published : 2006-09-14 00:07
Updated : 2024-11-21 00:13
NVD link : CVE-2006-3454
Mitre link : CVE-2006-3454
CVE.ORG link : CVE-2006-3454
JSON object : View
Products Affected
symantec
- norton_antivirus
- client_security
CWE