Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2007-3699

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
0
Attacker Value
Unknown

CVE-2007-0447

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
0
Attacker Value
Unknown

CVE-2007-1281

Disclosure Date: March 06, 2007 (last updated October 04, 2023)
Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
0
Attacker Value
Unknown

CVE-2007-0125

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.
0
Attacker Value
Unknown

CVE-2006-0232

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
0
Attacker Value
Unknown

CVE-2006-0231

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.
0
Attacker Value
Unknown

CVE-2006-0230

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.
0
Attacker Value
Unknown

CVE-2005-3225

Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Multiple interpretation error in unspecified versions of (1) eTrust-Iris and (2) eTrust-Vet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
0
Attacker Value
Unknown

CVE-2005-3217

Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
0
Attacker Value
Unknown

CVE-2005-2758

Disclosure Date: October 05, 2005 (last updated February 22, 2025)
Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow.
0