Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/62412 - | |
References | () http://secunia.com/advisories/38654 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/509717/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/38217 - | |
References | () http://www.securitytracker.com/id?1023628 - | |
References | () http://www.securitytracker.com/id?1023629 - | |
References | () http://www.securitytracker.com/id?1023630 - | |
References | () http://www.securitytracker.com/id?1023631 - | |
References | () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_01 - | |
References | () http://www.vupen.com/english/advisories/2010/0411 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/56357 - |
Information
Published : 2010-02-23 20:30
Updated : 2024-11-21 01:11
NVD link : CVE-2010-0107
Mitre link : CVE-2010-0107
CVE.ORG link : CVE-2010-0107
JSON object : View
Products Affected
symantec
- norton_360
- client_security
- norton_antivirus
- norton_internet_security
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer