MEDIUM · 4.9

CVE-2006-4855

The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS ...

Vulnerability Description

The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.

CVSS Score

4.9

MEDIUM

AV:L/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecClient Security1.0
SymantecHost IdsAll versions
SymantecNorton Antivirus2.1
SymantecNorton Internet Security2003
SymantecNorton Personal Firewall2003
SymantecNorton System Works2003_professional_edition
SymantecPcanywhere11.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-4855?

CVE-2006-4855 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS ...

How severe is CVE-2006-4855?

CVE-2006-4855 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4855?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Client Security, Symantec Host Ids, Symantec Norton Antivirus, Symantec Norton Internet Security, Symantec Norton Personal Firewall.