| Vulnerability Name: | CVE-2006-3456 (CCN-34200) | ||||||||
| Assigned: | 2006-07-07 | ||||||||
| Published: | 2007-05-09 | ||||||||
| Updated: | 2017-07-20 | ||||||||
| Summary: | The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. Note: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771. | ||||||||
| CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-94 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-3456 Source: IDEFENSE Type: Vendor Advisory 20070509 Symantec Norton Internet Security 2006 COM Object Security ByPass Vulnerability Source: OSVDB Type: UNKNOWN 35075 Source: CCN Type: SA25172 Symantec Products NAVOpts.dll ActiveX Control Security Bypass Vulnerability Source: SECUNIA Type: Vendor Advisory 25172 Source: CCN Type: SECTRACK ID: 1018031 Norton Internet Security `NAVOPTS.DLL` ActiveX Control Lets Remote Users Execute Arbitrary Code Source: CCN Type: Symantec Web site Symantec - LiveUpdate files Source: CCN Type: OSVDB ID: 35075 Symantec Multiple Products NAVOpts.dll ActiveX Arbitrary Code Execution Source: CCN Type: OSVDB ID: 36115 Symantec Multiple Products Internet Email Auto-Protect Outbound E-mail Handling Overflow Source: BID Type: UNKNOWN 23822 Source: CCN Type: BID-23822 Symantec Norton Antivirus NAVOPTS.DLL ActiveX Control Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1018031 Source: CCN Type: SYM07-005 Symantec COM object security bypass Source: CONFIRM Type: Vendor Advisory http://www.symantec.com/avcenter/security/Content/2007.05.09.html Source: VUPEN Type: Vendor Advisory ADV-2007-1751 Source: XF Type: UNKNOWN symantec-navopts-security-bypass(34200) Source: XF Type: UNKNOWN symantec-navopts-security-bypass(34200) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 05.09.07 Symantec Norton Internet Security 2006 COM Object Security ByPass Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||