CVE-2010-0107

Symantec Client Security 3.0.x-3.1.x - Buffer Overflow in SYMLTCOM.dll ActiveX Control

Title source: llm
STIX 2.1

Description

Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/62412
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509717/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023630
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38654
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56357
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0411
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023631
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38217
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023628
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023629

Scores

EPSS 0.2711
EPSS Percentile 96.5%

Details

CWE
CWE-119
Status published
Products (28)
symantec/client_security 3.0
symantec/client_security 3.0.1.1000
symantec/client_security 3.0.1.1001
symantec/client_security 3.0.1.1007
symantec/client_security 3.0.1.1008
symantec/client_security 3.0.1.1009
symantec/client_security 3.0.2
symantec/client_security 3.0.2.2000
symantec/client_security 3.0.2.2001
symantec/client_security 3.0.2.2002
... and 18 more
Published Feb 23, 2010
Tracked Since Feb 18, 2026