Vulnerability Details CVE-2005-0249
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.106
EPSS Ranking 92.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2005-0249
-
cpe:2.3:a:symantec:antivirus_scan_engine:-
-
cpe:2.3:a:symantec:antivirus_scan_engine:4.0
-
cpe:2.3:a:symantec:antivirus_scan_engine:4.1
-
cpe:2.3:a:symantec:antivirus_scan_engine:4.1.8
-
cpe:2.3:a:symantec:antivirus_scan_engine:4.1.9
-
cpe:2.3:a:symantec:antivirus_scan_engine:4.3
-
cpe:2.3:a:symantec:brightmail_antispam:4.0
-
cpe:2.3:a:symantec:brightmail_antispam:5.5
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.434
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.437
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.446
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.457
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.460
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.464
-
cpe:2.3:a:symantec:client_security:1.0.1_build_8.01.471
-
cpe:2.3:a:symantec:client_security:1.1.1_mr1_build_8.1.1.314a
-
cpe:2.3:a:symantec:client_security:1.1.1_mr2_build_8.1.1.319
-
cpe:2.3:a:symantec:client_security:1.1.1_mr3_build_8.1.1.323
-
cpe:2.3:a:symantec:client_security:1.1.1_mr4_build_8.1.1.329
-
cpe:2.3:a:symantec:client_security:1.1.1_mr5_build_8.1.1.336
-
cpe:2.3:a:symantec:gateway_security:1.0
-
cpe:2.3:a:symantec:gateway_security:2.0
-
cpe:2.3:a:symantec:gateway_security:2.0.1
-
cpe:2.3:a:symantec:mail_security:4.0
-
cpe:2.3:a:symantec:mail_security:4.1
-
cpe:2.3:a:symantec:mail_security:4.5_build_719
-
cpe:2.3:a:symantec:norton_antivirus:2.18_build_83
-
cpe:2.3:a:symantec:norton_antivirus:2004
-
cpe:2.3:a:symantec:norton_antivirus:8.01.434
-
cpe:2.3:a:symantec:norton_antivirus:8.01.437
-
cpe:2.3:a:symantec:norton_antivirus:8.01.446
-
cpe:2.3:a:symantec:norton_antivirus:8.01.457
-
cpe:2.3:a:symantec:norton_antivirus:8.01.460
-
cpe:2.3:a:symantec:norton_antivirus:8.01.464
-
cpe:2.3:a:symantec:norton_antivirus:8.01.471
-
cpe:2.3:a:symantec:norton_antivirus:8.1.1.319
-
cpe:2.3:a:symantec:norton_antivirus:8.1.1.323
-
cpe:2.3:a:symantec:norton_antivirus:8.1.1.329
-
cpe:2.3:a:symantec:norton_antivirus:8.1.1_build8.1.1.314a
-
cpe:2.3:a:symantec:norton_antivirus:9.0
-
cpe:2.3:a:symantec:norton_internet_security:2004
-
cpe:2.3:a:symantec:norton_system_works:2004
-
cpe:2.3:a:symantec:sav_filter_domino_nt_ports:build3.0.5
-
cpe:2.3:a:symantec:sav_filter_for_domino_nt:3.1.1
-
cpe:2.3:a:symantec:web_security:3.01.59
-
cpe:2.3:a:symantec:web_security:3.01.60
-
cpe:2.3:a:symantec:web_security:3.01.61
-
cpe:2.3:a:symantec:web_security:3.01.62
-
cpe:2.3:a:symantec:web_security:3.01.63
-
cpe:2.3:a:symantec:web_security:3.01.67
-
cpe:2.3:a:symantec:web_security:3.01.68