Vulnerability Description
Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Client Security | 3.0 |
| Symantec | Norton 360 | 1.0 |
| Symantec | Norton Antivirus | 2006 |
| Symantec | Norton Internet Security | 2006 |
Related Weaknesses (CWE)
References
- http://osvdb.org/62412
- http://secunia.com/advisories/38654Vendor Advisory
- http://www.securityfocus.com/archive/1/509717/100/0/threaded
- http://www.securityfocus.com/bid/38217
- http://www.securitytracker.com/id?1023628
- http://www.securitytracker.com/id?1023629
- http://www.securitytracker.com/id?1023630
- http://www.securitytracker.com/id?1023631
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securit
- http://www.vupen.com/english/advisories/2010/0411Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56357
- http://osvdb.org/62412
- http://secunia.com/advisories/38654Vendor Advisory
- http://www.securityfocus.com/archive/1/509717/100/0/threaded
- http://www.securityfocus.com/bid/38217
FAQ
What is CVE-2010-0107?
CVE-2010-0107 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3....
How severe is CVE-2010-0107?
CVE-2010-0107 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0107?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Client Security, Symantec Norton 360, Symantec Norton Antivirus, Symantec Norton Internet Security.