CVE-2004-0920

Symantec Norton AntiVirus <2004 - Code Injection

Title source: llm
STIX 2.1

Description

Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17603
Various Sources third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=147&type=vulnerabilities

Scores

EPSS 0.0071
EPSS Percentile 72.4%

Details

Status published
Products (1)
symantec/norton_antivirus < 2.1
Published Nov 03, 2004
Tracked Since Feb 18, 2026