CVE-2006-3456
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.
El control ActiveX Symantec NAVOPTS.DLL (también se conoce como Symantec.Norton.AntiVirus.NAVOptions) versión 12.2.0.13, tal y como es usado en Norton AntiVirus, Internet Security y System Works 2005 y 2006, está diseñado para usarse únicamente en navegadores web integrados en aplicaciones, lo que permite atacantes remotos "crash the control" por medio de vectores no especificados relacionados con el contenido en un sitio web, y colocar Internet Explorer en un "defunct state" en el que los atacantes remotos pueden ejecutar código arbitrario además de otros controles ActiveX de Symantec, independientemente de si están marcados como seguros para el scripting. NOTA: este CVE fue utilizado inadvertidamente para un problema de protección automática de correo electrónico, pero a ese problema ha sido asignado CVE-2007-3771.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-07 CVE Reserved
- 2007-05-10 CVE Published
- 2024-03-14 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/35075 | Vdb Entry | |
http://www.securityfocus.com/bid/23822 | Vdb Entry | |
http://www.securitytracker.com/id?1018031 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34200 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=529 | 2017-07-20 | |
http://secunia.com/advisories/25172 | 2017-07-20 | |
http://www.symantec.com/avcenter/security/Content/2007.05.09.html | 2017-07-20 | |
http://www.vupen.com/english/advisories/2007/1751 | 2017-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 2005 Search vendor "Symantec" for product "Norton Antivirus" and version "2005" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Antivirus Search vendor "Symantec" for product "Norton Antivirus" | 2006 Search vendor "Symantec" for product "Norton Antivirus" and version "2006" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Internet Security Search vendor "Symantec" for product "Norton Internet Security" | 2005 Search vendor "Symantec" for product "Norton Internet Security" and version "2005" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton Internet Security Search vendor "Symantec" for product "Norton Internet Security" | 2006 Search vendor "Symantec" for product "Norton Internet Security" and version "2006" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton System Works Search vendor "Symantec" for product "Norton System Works" | 2005 Search vendor "Symantec" for product "Norton System Works" and version "2005" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Norton System Works Search vendor "Symantec" for product "Norton System Works" | 2006 Search vendor "Symantec" for product "Norton System Works" and version "2006" | - |
Affected
|