Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-3961


Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.


Published

2006-08-01T21:04:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mcafee antispyware 2005 Yes
Application mcafee antispyware 2006 Yes
Application mcafee internet_security_suite 2004 Yes
Application mcafee internet_security_suite 2005 Yes
Application mcafee internet_security_suite 2006 Yes
Application mcafee personal_firewall_plus 2004 Yes
Application mcafee personal_firewall_plus 2005 Yes
Application mcafee personal_firewall_plus 2006 Yes
Application mcafee privacy_service 2004 Yes
Application mcafee privacy_service 2005 Yes
Application mcafee privacy_service 2006 Yes
Application mcafee quickclean 2004 Yes
Application mcafee quickclean 2005 Yes
Application mcafee quickclean 2006 Yes
Application mcafee security_center 4.3 Yes
Application mcafee security_center 6.0 Yes
Application mcafee security_center 6.0.22 Yes
Application mcafee security_center 6.0.23 Yes
Application mcafee spamkiller 5.0 Yes
Application mcafee spamkiller 6.0 Yes
Application mcafee spamkiller 7.0 Yes
Application mcafee virusscan 2004 Yes
Application mcafee virusscan 2005 Yes
Application mcafee virusscan 2006 Yes
Application mcafee wireless_home_network_security 2006 Yes

References