CVE-2006-6490
Last modified
CVE-2006-6490 is a vulnerability of currently unknown severity. Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.. EPSS estimates a 10.34% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Supportsoft | Scriptrunner | All versions |
| Supportsoft | Smartissue | All versions |
| Symantec | Automated Support Assistant | All versions |
| Symantec | Norton Antivirus | 2006 |
| Symantec | Norton Internet Security | 2006 |
| Symantec | Norton System Works | 2006 |
References
- http://www.kb.cert.org/vuls/id/441785US Government Resource
- http://www.kb.cert.org/vuls/id/441785US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6490?
How severe is CVE-2006-6490?
How do I fix CVE-2006-6490?
Are you affected by CVE-2006-6490?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
