Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-3456
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3456

Description:
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/34200

ST
  1018031

SAID
  Secunia Advisory: SA25172

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=529

CONFIRM
  http://www.symantec.com/avcenter/security/Content/2007.05.09.html

BID
  23822


Return to the previous page.