CVE-2010-0107
Symantec Client Security 3.0.x-3.1.x - Buffer Overflow in SYMLTCOM.dll ActiveX Control
Title source: llmDescription
Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
References (11)
Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/62412
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509717/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023630
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38654
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56357
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0411
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023631
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38217
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023628
Third Party Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_01
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023629
Scores
EPSS
0.2711
EPSS Percentile
96.5%
Details
CWE
CWE-119
Status
published
Products (28)
symantec/client_security
3.0
symantec/client_security
3.0.1.1000
symantec/client_security
3.0.1.1001
symantec/client_security
3.0.1.1007
symantec/client_security
3.0.1.1008
symantec/client_security
3.0.1.1009
symantec/client_security
3.0.2
symantec/client_security
3.0.2.2000
symantec/client_security
3.0.2.2001
symantec/client_security
3.0.2.2002
... and 18 more
Published
Feb 23, 2010
Tracked Since
Feb 18, 2026