CVE-2004-0375 – Symantec Client Firewall Products 5 - 'SYMNDIS.SYS' Driver Remote Denial of Service
https://notcve.org/view.php?id=CVE-2004-0375
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero. SIMNDIS.SYS en Symantec Norton Internet Securiy 2003 y 2004, Norton Personal Firewall 2003 y 2004, Client Firewall 5.01 y 5.1.1, y Client Security 1.0 y 1.1 permite a atacantes remotos causar una denegación de servicio (bucle infinito) mediante un paquete TCP con (1) opción SACK o (2) opción Suma de Comprobación de Datos Alternativa seguida por una longitud cero. • https://www.exploit-db.com/exploits/23846 http://marc.info/?l=bugtraq&m=108275582432246&w=2 http://securitytracker.com/id?1009379 http://securitytracker.com/id?1009380 http://www.eeye.com/html/Research/Upcoming/20040309.html http://www.securityfocus.com/bid/9912 http://www.symantec.com/avcenter/security/Content/2004.04.20.html https://exchange.xforce.ibmcloud.com/vulnerabilities/15433 https://exchange.xforce.ibmcloud.com/vulnerabilities/15936 •
CVE-2004-0364
https://notcve.org/view.php?id=CVE-2004-0364
The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method. El componente Activex WrWrapNISUM (WrapUM.dll) de Norton Internet Security 2004 está marcado como seguro para secuencias de comandos, lo que permite a atacantes remotos ejecutar programas arbitrarios mediante el método LaunchURL. • http://marc.info/?l=bugtraq&m=107970885922442&w=2 http://marc.info/?l=bugtraq&m=107980262324362&w=2 http://secunia.com/advisories/11168 http://www.kb.cert.org/vuls/id/549054 http://www.nextgenss.com/advisories/nisrce.txt http://www.sarc.com/avcenter/security/Content/2004.03.19.html http://www.securityfocus.com/bid/9915 https://exchange.xforce.ibmcloud.com/vulnerabilities/15538 •
CVE-2003-0994
https://notcve.org/view.php?id=CVE-2003-0994
The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges. La funcionalidad gui para una sesión interactiva en ymantec LiveUpdate 1.70.x hasta la 1.90.x (usadas en Norton Internet Security 2001 hasta 2004, SystemWorks 2001 hasta 2004, y AntiVirus y Norton AntiVirus Pro 2001 hasta 2004, AntiVirus for Handhelds v3.0) permite que usuarios locales obtengan privilegios SYSTEM. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html http://marc.info/?l=bugtraq&m=107393473928245&w=2 http://www.osvdb.org/3428 http://www.secnetops.biz/research/SRT2004-01-09-1022.txt •
CVE-2003-1149 – Symantec Norton Internet Security 2003 6.0.4.34 - Error Message Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2003-1149
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page. • https://www.exploit-db.com/exploits/23304 http://secunia.com/advisories/10067 http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html http://www.osvdb.org/2714 http://www.securityfocus.com/archive/1/342548 http://www.securityfocus.com/bid/8904 https://exchange.xforce.ibmcloud.com/vulnerabilities/13528 •
CVE-2002-1695
https://notcve.org/view.php?id=CVE-2002-1695
Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running. • http://online.securityfocus.com/archive/1/250591 http://www.securityfocus.com/bid/3888 https://exchange.xforce.ibmcloud.com/vulnerabilities/7919 •