Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-1774 | First vendor Publication | 2002-12-31 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1774 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-52 | Embedding NULL Bytes |
CAPEC-53 | Postfix, Null Terminate, and Backslash |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
6261 | Symantec Norton Anti-Virus Modified MIME Email Scan Bypass Symantec Norton AntiVirus contains a flaw that may allow a remote attacker to bypass antivirus policies. The issue is triggered when inserting NULL characters into the MIME type before the virus type is defined, which would remain undetected by the incoming email protection feature. It is possible that the flaw may allow a remote attacker to execute arbitrary code, resulting in a loss of integrity. |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:37 |
|
2024-11-28 12:05:20 |
|
2024-08-08 09:28:14 |
|
2024-05-17 09:28:45 |
|
2024-05-14 21:28:32 |
|
2024-04-11 09:28:48 |
|
2024-03-21 09:28:51 |
|
2023-11-07 21:48:11 |
|
2021-05-04 12:01:51 |
|
2021-04-22 01:01:59 |
|
2020-05-23 00:15:12 |
|
2017-07-11 12:01:13 |
|
2013-05-11 12:14:19 |
|