CVE-2006-6490
high · 10Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2007-02-22
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| supportsoft | scriptrunner | all versions |
| supportsoft | smartissue | all versions |
| symantec | automated_support_assistant | all versions |
| symantec | norton_antivirus | 2006 |
| symantec | norton_internet_security | 2006 |
| symantec | norton_system_works | 2006 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478
- http://osvdb.org/33481
- http://osvdb.org/33482
- http://secunia.com/advisories/24246
- http://secunia.com/advisories/24251
- http://www.kb.cert.org/vuls/id/441785
- http://www.securityfocus.com/archive/1/461147/100/0/threaded
- http://www.securityfocus.com/bid/22564
- http://www.securitytracker.com/id?1017688
- http://www.securitytracker.com/id?1017689
- http://www.securitytracker.com/id?1017690
- http://www.securitytracker.com/id?1017691
- http://www.symantec.com/avcenter/security/Content/2007.02.22.html
- http://www.vupen.com/english/advisories/2007/0703
- http://www.vupen.com/english/advisories/2007/0704
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32636
- http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478
- http://osvdb.org/33481
- http://osvdb.org/33482
- http://secunia.com/advisories/24246
- http://secunia.com/advisories/24251
- http://www.kb.cert.org/vuls/id/441785
- http://www.securityfocus.com/archive/1/461147/100/0/threaded
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-6490