Vulnerability Details CVE-2010-0107
Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.271
EPSS Ranking 96.1%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2010-0107
-
cpe:2.3:a:symantec:client_security:3.0
-
cpe:2.3:a:symantec:client_security:3.0.1.1000
-
cpe:2.3:a:symantec:client_security:3.0.1.1001
-
cpe:2.3:a:symantec:client_security:3.0.1.1007
-
cpe:2.3:a:symantec:client_security:3.0.1.1008
-
cpe:2.3:a:symantec:client_security:3.0.1.1009
-
cpe:2.3:a:symantec:client_security:3.0.2
-
cpe:2.3:a:symantec:client_security:3.0.2.2000
-
cpe:2.3:a:symantec:client_security:3.0.2.2001
-
cpe:2.3:a:symantec:client_security:3.0.2.2002
-
cpe:2.3:a:symantec:client_security:3.0.2.2010
-
cpe:2.3:a:symantec:client_security:3.0.2.2011
-
cpe:2.3:a:symantec:client_security:3.0.2.2020
-
cpe:2.3:a:symantec:client_security:3.0.2.2021
-
cpe:2.3:a:symantec:client_security:3.1
-
cpe:2.3:a:symantec:client_security:3.1.0.396
-
cpe:2.3:a:symantec:client_security:3.1.0.401
-
cpe:2.3:a:symantec:client_security:3.1.396
-
cpe:2.3:a:symantec:client_security:3.1.400
-
cpe:2.3:a:symantec:client_security:3.1.401
-
cpe:2.3:a:symantec:norton_360:1.0
-
cpe:2.3:a:symantec:norton_360:2.0
-
cpe:2.3:a:symantec:norton_antivirus:2006
-
cpe:2.3:a:symantec:norton_antivirus:2007
-
cpe:2.3:a:symantec:norton_antivirus:2008
-
cpe:2.3:a:symantec:norton_internet_security:2006
-
cpe:2.3:a:symantec:norton_internet_security:2007
-
cpe:2.3:a:symantec:norton_internet_security:2008