CVE-2007-2955
Summary
| CVE | CVE-2007-2955 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-08-09 21:17:00 UTC |
| Updated | 2017-07-29 01:31:00 UTC |
| Description | Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Norton Antivirus | 2006 | All | All | All |
| Application | Symantec | Norton Antivirus | 2006 | All | All | All |
| Application | Symantec | Norton Internet Security | 2005 | All | anti_spyware | All |
| Application | Symantec | Norton Internet Security | 2006 | All | All | All |
| Application | Symantec | Norton Internet Security | 2005 | All | anti_spyware | All |
| Application | Symantec | Norton Internet Security | 2006 | All | All | All |
| Application | Symantec | Norton System Works | 2006 | All | All | All |
| Application | Symantec | Norton System Works | 2006 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Norton Anti-Virus Input Validation Flaw in NAVCOMUI.DLL ActiveX Controls Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Symantec Products NavComUI ActiveX Control Code Execution - Advisories - Secunia | SECUNIA | secunia.com | |
| Norton Internet Security Input Validation Flaw in NAVCOMUI.DLL ActiveX Controls Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Symantec ActiveX Control Input Validation Error | CONFIRM | www.symantec.com | |
| SecurityTracker.com Archives - Norton System Works Input Validation Flaw in NAVCOMUI.DLL ActiveX Controls Let Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| Symantec Products NavComUI ActiveX Control Code Execution - Secunia Research - Secunia | MISC | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.