CVE-2005-0249
https://notcve.org/view.php?id=CVE-2005-0249
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. • http://securitytracker.com/id?1013133 http://www.kb.cert.org/vuls/id/107822 http://www.symantec.com/avcenter/security/Content/2005.02.08.html http://xforce.iss.net/xforce/alerts/id/187 https://exchange.xforce.ibmcloud.com/vulnerabilities/18869 •
CVE-2004-0445 – Symantec Multiple Firewall - DNS Response Denial of Service
https://notcve.org/view.php?id=CVE-2004-0445
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself. El controlador SYMDNS.SYS de Symantec Norton Internet Security y Professional 2002 a 2004, Norton Personal Firewall 2002 a 2004, Norton AntiSpam 2004, Client Firewall 5.01 y 5.1.1, Client Securiy 1.0 a 2.0 permite a atacantes remotos causar una denegación de servicio (consumición de CPU en un buble infinito) mediante una respuesta DNS con un puntero de nombre comprimido que apunta a sí mismo. • https://www.exploit-db.com/exploits/299 http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html http://secunia.com/advisories/11066 http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html http://securitytracker.com/id?1010144 http://securitytracker.com/id?1010145 http://securitytracker.com/id?1010146 http://www.ciac.org/ciac/bulletins/o-141.shtml http://www.kb.cert.org/vuls/id/682110 http://www.osvdb.org/6100 http://www.securityf •
CVE-2004-0444
https://notcve.org/view.php?id=CVE-2004-0444
Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components. Múltiples vulenrabilidades en SYMDNS.SYS de Symantec Noton Internet Security y Professional 2002 a 2004, Norton Persnoal Firewall 2002 a 2004, Norton AntiSpam 2004, Client Firewal 5.01 y 5.1.1, y Client Security 1.0 a 2.0 permite a atacantes remotos causar una denegación de servicio o ejecutar código de su elección mediante (1) un byte de longitud manipulado en la rutina de decodificación de primer nivel del Servicio de Nombres de NetBIOS (NBNS) que modifica una variable de índice que conduce a un desbordamiento de búfer en la pila, (2) un problema de corrupción del montón en una respuesta NBNS a la que le faltan ciertos campor RR, y (3) un desbordamiento de búfer basado en la pila en el componente DNS mediante un Registro de Recurso (RR) con un nombre canónico (CNAME) largo compuest de muchos componentes más pequeños. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021360.html http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021361.html http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021362.html http://secunia.com/advisories/11066 http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html http://securitytracker.com/id?1010144 http://securitytracker.com/id?1010145 http://securitytracker.com/id?1010146 http://www.ciac.org/ciac/bulletins/o-141. •
CVE-2004-0363 – Norton AntiSpam 2004 - SymSpamHelper ActiveX Control Buffer Overflow
https://notcve.org/view.php?id=CVE-2004-0363
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method. Desbordamiento de búfer basado en la pila en el componente ActiveX SymSpamHelper (symspam.dll) en Norton AntiSpam 2004, usado en Norton Internet Security 2004, permite a atacantes remotos ejecutar código arbitrario mediante un parámetro largo en el método LaunchCustomRuleWizard. • https://www.exploit-db.com/exploits/16595 http://marc.info/?l=bugtraq&m=107970870606638&w=2 http://marc.info/?l=bugtraq&m=107980262324362&w=2 http://secunia.com/advisories/11169 http://www.kb.cert.org/vuls/id/344718 http://www.nextgenss.com/advisories/antispam.txt http://www.sarc.com/avcenter/security/Content/2004.03.19.html http://www.securityfocus.com/bid/9916 https://exchange.xforce.ibmcloud.com/vulnerabilities/15536 •