LOW · 1.9

CVE-2010-0106

The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers...

Vulnerability Description

The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.

CVSS Score

1.9

LOW

AV:L/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
SymantecAntivirus10.0
SymantecClient Security3.0
SymantecEndpoint Protection11.0

References

FAQ

What is CVE-2010-0106?

CVE-2010-0106 is a vulnerability with a CVSS score of 1.9 (LOW). The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers...

How severe is CVE-2010-0106?

CVE-2010-0106 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0106?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Antivirus, Symantec Client Security, Symantec Endpoint Protection.