Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1428

Опубликовано: 29 апр. 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:symantec:antivirus:*:*:*:*:*:*:*:*
Версия до 10.1 (включая)
cpe:2.3:a:symantec:antivirus:10.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.3:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.4:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.5:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.6:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.7:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.8:*:*:*:*:*:*:*
cpe:2.3:a:symantec:antivirus:10.0.9:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_360:1.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:*:anti_spyware:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:*:professional:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:11.0:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:11.0.9:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005:11.5.6.14:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2005_contains_nav_11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2006:*:professional:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01393
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."

EPSS

Процентиль: 80%
0.01393
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79