10
CVSSv2

CVE-2005-2758

Published: 05/10/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote malicious users to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec antivirus scan engine 4.3

symantec antivirus scan engine 4.0

symantec antivirus scan engine for network attached storage 4.3