Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-3021


Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export.


Published

2007-06-05T21:30:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application symantec client_security 3.1 Yes
Application symantec client_security 3.1.394 Yes
Application symantec client_security 3.1.396 Yes
Application symantec client_security 3.1.400 Yes
Application symantec client_security 3.1.401 Yes
Application symantec norton_antivirus 10.0.2.2021 Yes
Application symantec norton_antivirus 10.1 Yes
Application symantec norton_antivirus 10.1.396 Yes
Application symantec norton_antivirus 10.1.400 Yes
Application symantec norton_antivirus 10.1.401 Yes
Application symantec reporting_server ≤ 1.0.197.0 Yes

References