CVE-2004-0363
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 66.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 66.57% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- symantec/norton antispam
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=107970870606638&w=2
- http://marc.info/?l=bugtraq&m=107980262324362&w=2
- http://secunia.com/advisories/11169
- http://www.kb.cert.org/vuls/id/344718US Government Resource
- http://www.nextgenss.com/advisories/antispam.txtPatch, Vendor Advisory
- http://www.sarc.com/avcenter/security/Content/2004.03.19.html
- http://www.securityfocus.com/bid/9916Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15536
- http://marc.info/?l=bugtraq&m=107970870606638&w=2
- http://marc.info/?l=bugtraq&m=107980262324362&w=2
- http://secunia.com/advisories/11169
- http://www.kb.cert.org/vuls/id/344718US Government Resource
- http://www.nextgenss.com/advisories/antispam.txtPatch, Vendor Advisory
- http://www.sarc.com/avcenter/security/Content/2004.03.19.html
- http://www.securityfocus.com/bid/9916Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15536
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.