CVE-2004-0363
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 67%
from disclosure to weapon2238 days
Published on NVDMar 23
1st PoC+2238d
metasploitMar 19
exploitation probability
67%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16595unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=107970870606638&w=2http://marc.info/?l=bugtraq&m=107980262324362&w=2http://secunia.com/advisories/11169https://exchange.xforce.ibmcloud.com/vulnerabilities/15536http://www.kb.cert.org/vuls/id/344718http://www.nextgenss.com/advisories/antispam.txthttp://www.sarc.com/avcenter/security/Content/2004.03.19.htmlhttp://www.securityfocus.com/bid/9916