Vulnerabilities > CVE-2004-1910 - Denial Of Service vulnerability in Symantec Security Check Virus Detection COM Object

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
symantec
exploit available

Summary

rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.

Vulnerable Configurations

Part Description Count
Application
Symantec
1

Exploit-Db

descriptionSymantec Security Check Virus Detection COM Object Denial Of Service Vulnerability. CVE-2004-1910. Dos exploit for windows platform
idEDB-ID:23919
last seen2016-02-02
modified2004-04-07
published2004-04-07
reporterRafel Ivgi The-Insider
sourcehttps://www.exploit-db.com/download/23919/
titleSymantec Security Check Virus Detection COM Object Denial of Service Vulnerability