Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-2955 | First vendor Publication | 2007-08-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2955 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 2 | |
Application | 1 |
SAINT Exploits
Description | Link |
---|---|
Symantec Norton NavComUI ActiveX control vulnerability | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
36477 | Symantec Multiple Products NavComUI ActiveX Multiple Property Arbitrary Code... |
Snort® IPS/IDS
Date | Description |
---|---|
2016-05-17 | Symantec NavComUI AxSysListView32OAA ActiveX function call access attempt RuleID : 38540 - Revision : 1 - Type : BROWSER-PLUGINS |
2016-05-17 | Symantec NavComUI AxSysListView32OAA ActiveX clsid access attempt RuleID : 38539 - Revision : 1 - Type : BROWSER-PLUGINS |
2016-05-17 | Symantec NavComUI AxSysListView32 ActiveX function call access attempt RuleID : 38538 - Revision : 1 - Type : BROWSER-PLUGINS |
2016-05-17 | Symantec NavComUI AxSysListView32 ActiveX clsid access attempt RuleID : 38537 - Revision : 1 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec NavComUI AxSysListView32OAA ActiveX function call unicode access RuleID : 12253 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec NavComUI AxSysListView32OAA ActiveX function call access attempt RuleID : 12252 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec NavComUI AxSysListView32OAA ActiveX clsid unicode access RuleID : 12251 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec NavComUI AxSysListView32OAA ActiveX clsid access attempt RuleID : 12250 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec NavComUI AxSysListView32 ActiveX function call unicode access RuleID : 12249 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec NavComUI AxSysListView32 ActiveX function call access attempt RuleID : 12248 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec NavComUI AxSysListView32 ActiveX clsid unicode access RuleID : 12247 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Symantec NavComUI AxSysListView32 ActiveX clsid access attempt RuleID : 12246 - Revision : 11 - Type : BROWSER-PLUGINS |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:16:35 |
|
2024-11-28 12:12:29 |
|
2021-05-04 12:05:51 |
|
2021-04-22 01:06:24 |
|
2020-05-23 00:19:52 |
|
2017-07-29 12:02:17 |
|
2016-04-26 16:11:59 |
|
2014-01-19 21:24:11 |
|
2013-05-11 10:27:13 |
|