Lucene search

K
nvd[email protected]NVD:CVE-2006-3456
HistoryMay 11, 2007 - 10:19 a.m.

CVE-2006-3456

2007-05-1110:19:00
CWE-94
web.nvd.nist.gov
5

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.01

Percentile

83.6%

The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to “crash the control” via unspecified vectors related to content on a web site, and place Internet Explorer into a “defunct state” in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.

Affected configurations

Nvd
Node
symantecnorton_antivirusMatch2005
OR
symantecnorton_antivirusMatch2006
OR
symantecnorton_internet_securityMatch2005
OR
symantecnorton_internet_securityMatch2006
OR
symantecnorton_system_worksMatch2005
OR
symantecnorton_system_worksMatch2006
VendorProductVersionCPE
symantecnorton_antivirus2005cpe:2.3:a:symantec:norton_antivirus:2005:*:*:*:*:*:*:*
symantecnorton_antivirus2006cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*
symantecnorton_internet_security2005cpe:2.3:a:symantec:norton_internet_security:2005:*:*:*:*:*:*:*
symantecnorton_internet_security2006cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
symantecnorton_system_works2005cpe:2.3:a:symantec:norton_system_works:2005:*:*:*:*:*:*:*
symantecnorton_system_works2006cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.01

Percentile

83.6%