Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-0312


Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method. NOTE: some of these details are obtained from third party information.


Published

2008-04-08T17:05:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microsoft windows * No
Application symantec norton_360 1.0 Yes
Application symantec norton_antivirus 2006 Yes
Application symantec norton_antivirus 2007 Yes
Application symantec norton_antivirus 2008 Yes
Application symantec norton_internet_security 2006 Yes
Application symantec norton_internet_security 2007 Yes
Application symantec norton_internet_security 2008 Yes
Application symantec norton_system_works 2006 Yes
Application symantec norton_system_works 2007 Yes
Application symantec norton_system_works 2008 Yes

References