Vulnerability Details CVE-2006-3456
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.06
EPSS Ranking 90.2%
CVSS Severity
CVSS v2 Score 8.5
Products affected by CVE-2006-3456
-
cpe:2.3:a:symantec:norton_antivirus:2005
-
cpe:2.3:a:symantec:norton_antivirus:2006
-
cpe:2.3:a:symantec:norton_internet_security:2005
-
cpe:2.3:a:symantec:norton_internet_security:2006
-
cpe:2.3:a:symantec:norton_system_works:2005
-
cpe:2.3:a:symantec:norton_system_works:2006