Vulnerabilities > CVE-2006-6490 - Remote Buffer Overflow vulnerability in SupportSoft ActiveX Controls

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
supportsoft
symantec
critical

Summary

Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.

Saint

bid22564
descriptionSupportSoft tgctlsi.dll ActiveX control buffer overflow
idmisc_av_supportsofttgax
osvdb33481
titlesupportsoft_activex
typeclient