Show filters
595 Total Results
Displaying 461-470 of 595
Sort by:
Attacker Value
Unknown
CVE-2007-3022
Disclosure Date: June 05, 2007 (last updated October 04, 2023)
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.
0
Attacker Value
Unknown
CVE-2007-2917
Disclosure Date: June 01, 2007 (last updated October 04, 2023)
Multiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-2852
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name.
0
Attacker Value
Unknown
CVE-2007-2845
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB archive, resulting from an "integer cast around".
0
Attacker Value
Unknown
CVE-2007-2846
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the SIS unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted SIS archive, resulting from an "integer cast around."
0
Attacker Value
Unknown
CVE-2006-3456
Disclosure Date: May 11, 2007 (last updated October 04, 2023)
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.
0
Attacker Value
Unknown
CVE-2007-1673
Disclosure Date: May 09, 2007 (last updated October 04, 2023)
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
0
Attacker Value
Unknown
CVE-2007-1672
Disclosure Date: May 09, 2007 (last updated October 04, 2023)
avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
0
Attacker Value
Unknown
CVE-2007-1670
Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
0
Attacker Value
Unknown
CVE-2007-1793
Disclosure Date: April 02, 2007 (last updated October 04, 2023)
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.
0