SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-2955

Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code…

MEDIUM 6.8EPSS 4.03%

Does this matter?

Lower severity and a low EPSS score (4.03%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly property to AxSysListView32OAA.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
4.03% probability · 90th percentile
CISA KEV
Not listed
Affected
symantec/norton antivirus · symantec/norton internet security · symantec/norton system works
Source
PSIRT-CNA@flexerasoftware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.