CVE-2007-1689
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 64%
from disclosure to weapon1089 days
Published on NVDMay 16
1st PoC+1089d
metasploitMay 16
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16610unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/36164http://secunia.com/advisories/25290https://exchange.xforce.ibmcloud.com/vulnerabilities/34328http://www.kb.cert.org/vuls/id/983953http://www.securityfocus.com/archive/1/468779/100/0/threadedhttp://www.securityfocus.com/bid/23936http://www.securitytracker.com/id?1018073http://www.symantec.com/avcenter/security/Content/2007.05.16.htmlhttp://www.vupen.com/english/advisories/2007/1843