Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-6490 | First vendor Publication | 2007-02-22 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6490 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 | |
Application | 1 | |
Application | 1 | |
Application | 1 |
SAINT Exploits
Description | Link |
---|---|
SupportSoft tgctlsi.dll ActiveX control buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
33482 | SupportSoft ScriptRunner (tgctlsr.dll) ActiveX Overflow |
33481 | SupportSoft SmartIssue (tgctlsi.dll) ActiveX Overflow |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Symantec SupportSoft SmartIssue ActiveX function call unicode access RuleID : 16012 - Revision : 4 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec SupportSoft SmartIssue ActiveX function call access RuleID : 10395 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec SupportSoft SmartIssue ActiveX clsid unicode access RuleID : 10394 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec SupportSoft SmartIssue ActiveX clsid access RuleID : 10393 - Revision : 14 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec Support Controls SmartIssue ActiveX function call access RuleID : 10392 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec Support Controls SmartIssue ActiveX clsid unicode access RuleID : 10391 - Revision : 5 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec Support Controls SmartIssue ActiveX clsid access RuleID : 10390 - Revision : 13 - Type : BROWSER-PLUGINS |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:18:09 |
|
2024-11-28 12:10:48 |
|
2021-05-04 12:04:59 |
|
2021-04-22 01:05:34 |
|
2020-05-23 00:18:49 |
|
2018-10-18 00:19:50 |
|
2017-07-29 12:01:49 |
|
2016-06-28 16:01:23 |
|
2016-04-26 15:25:18 |
|
2014-01-19 21:23:41 |
|
2013-05-11 11:16:49 |
|