Описание
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:symantec:client_security:1.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:1.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:8.1:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:9.0:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:10.0:*:corporate:*:*:*:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
EPSS
Процентиль: 25%
0.00085
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other