Vulnerabilities > CVE-2004-0363 - Unspecified vulnerability in Symantec Norton Antispam 2004
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Norton AntiSpam 2004 SymSpamHelper ActiveX Control Buffer Overflow. CVE-2004-0363. Remote exploit for windows platform |
id | EDB-ID:16595 |
last seen | 2016-02-02 |
modified | 2010-05-09 |
published | 2010-05-09 |
reporter | metasploit |
source | https://www.exploit-db.com/download/16595/ |
title | Norton AntiSpam 2004 SymSpamHelper ActiveX Control Buffer Overflow |
Metasploit
description | This module exploits a stack buffer overflow in Norton AntiSpam 2004. When sending an overly long string to the LaunchCustomRuleWizard() method of symspam.dll (2004.1.0.147) an attacker may be able to execute arbitrary code. |
id | MSF:EXPLOIT/WINDOWS/BROWSER/NIS2004_ANTISPAM |
last seen | 2020-05-22 |
modified | 2017-10-05 |
published | 2009-01-10 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0363 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/nis2004_antispam.rb |
title | Norton AntiSpam 2004 SymSpamHelper ActiveX Control Buffer Overflow |
Packetstorm
data source | https://packetstormsecurity.com/files/download/83053/nis2004_antispam.rb.txt |
id | PACKETSTORM:83053 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | MC |
source | https://packetstormsecurity.com/files/83053/Norton-AntiSpam-2004-SymSpamHelper-ActiveX-Control-Buffer-Overflow.html |
title | Norton AntiSpam 2004 SymSpamHelper ActiveX Control Buffer Overflow |
Saint
bid | 9916 |
description | Norton AntiSpam 2004 SymSpamHelper ActiveX control buffer overflow |
id | misc_symspam |
osvdb | 6249 |
title | norton_antispam_symspam_rulewizard |
type | client |
References
- http://marc.info/?l=bugtraq&m=107970870606638&w=2
- http://marc.info/?l=bugtraq&m=107970870606638&w=2
- http://marc.info/?l=bugtraq&m=107980262324362&w=2
- http://marc.info/?l=bugtraq&m=107980262324362&w=2
- http://secunia.com/advisories/11169
- http://secunia.com/advisories/11169
- http://www.kb.cert.org/vuls/id/344718
- http://www.kb.cert.org/vuls/id/344718
- http://www.nextgenss.com/advisories/antispam.txt
- http://www.nextgenss.com/advisories/antispam.txt
- http://www.sarc.com/avcenter/security/Content/2004.03.19.html
- http://www.sarc.com/avcenter/security/Content/2004.03.19.html
- http://www.securityfocus.com/bid/9916
- http://www.securityfocus.com/bid/9916
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15536
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15536