CVE-2006-6490
https://notcve.org/view.php?id=CVE-2006-6490
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message. Múltiples desbordamiento de búfer en los controles ActiveX de SupportSoft (1) SmartIssue (tgctlsi.dll) y (2) ScriptRunner (tgctlsr.dll), tal y como se usan en Symantec Automated Support Assistant y Norton AntiVirus, Internet Security, y System Works 2006, permite a atacantes remotos ejecutar código de su elección mediante un mensaje HTML manipulado. • http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478 http://osvdb.org/33481 http://osvdb.org/33482 http://secunia.com/advisories/24246 http://secunia.com/advisories/24251 http://www.kb.cert.org/vuls/id/441785 http://www.securityfocus.com/archive/1/461147/100/0/threaded http://www.securityfocus.com/bid/22564 http://www.securitytracker.com/id?1017688 http://www.securitytracker.com/id?10 •
CVE-2006-5403
https://notcve.org/view.php?id=CVE-2006-5403
Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. Desbordamiento de buffer basado en pila en el Control de ActiveX usado en Symantec Automated Support Assistant, como el usado en el AntiVirus Norton, en Internet Security y System Works 2005 y 2006, permite a los atacantes remotos con la complicidad del usuario, causar la denegación de servicio (caída) y la posibilidad de ejecutar código de su elección mediante vectores no definidos. • http://secunia.com/advisories/22228 http://securityresponse.symantec.com/avcenter/security/Content/2006.10.05.html http://securitytracker.com/id?1016988 http://securitytracker.com/id?1016989 http://securitytracker.com/id?1016990 http://securitytracker.com/id?1016991 http://www.kb.cert.org/vuls/id/400601 http://www.securityfocus.com/bid/20348 http://www.vupen.com/english/advisories/2006/3929 https://exchange.xforce.ibmcloud.com/vulnerabilities/29363 •
CVE-2006-5404
https://notcve.org/view.php?id=CVE-2006-5404
Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspecified vectors. Vulnerabilidad no especificada en el Control de ActiveX usado en Symantec Automated Support Assistant, como el usado en el AntiVirus Norton, en Internet Security y System Works 2005 y 2006, permite a los atacantes remotos, con la complicidad del usuario, obtener información sensible mediante vectores no especificados. • http://secunia.com/advisories/22228 http://securityresponse.symantec.com/avcenter/security/Content/2006.10.05.html http://securitytracker.com/id?1016988 http://securitytracker.com/id?1016989 http://securitytracker.com/id?1016990 http://securitytracker.com/id?1016991 http://www.securityfocus.com/bid/20348 http://www.vupen.com/english/advisories/2006/3929 https://exchange.xforce.ibmcloud.com/vulnerabilities/29366 •