CVE-2007-1476 (CNNVD-200703-393)
LOW
有利用代码
中文标题:
Symantec Norton个人防火墙SymTDI驱动本地拒绝服务漏洞
英文标题:
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier,...
CVSS分数:
1.9
发布时间:
2007-03-16 21:00:00
漏洞类型:
授权问题
状态:
PUBLISHED
数据质量分数:
0.40
数据版本:
v4
漏洞描述
中文描述:
Symantec Norton个人防火墙是非常流行的防火墙软件。 Norton个人防火墙的驱动实现上存在漏洞,本地攻击者可能利用此漏洞导致系统崩溃。 Norton个人防火墙没有充分地保护其\Device\SymEvent驱动,且没有验证输入缓冲区,因此本地攻击者可以打开这个驱动并发送被认为是有效的任意数据。当在输入缓冲区中重组数据时驱动可能会执行无效的内存操作,导致整个操作系统拒绝服务。
英文描述:
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.
CWE类型:
CWE-20
标签:
dos
windows
David Matousek
OSVDB-35088
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| symantec | client_security | 2.0 | - | - |
cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.1 | - | - |
cpe:2.3:a:symantec:client_security:2.0.1:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.1_build_9.0.1.1000 | - | - |
cpe:2.3:a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1:*:*:*:*:*:*
|
| symantec | client_security | 2.0.2 | - | - |
cpe:2.3:a:symantec:client_security:2.0.2:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.2_build_9.0.2.1000 | - | - |
cpe:2.3:a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2:*:*:*:*:*:*
|
| symantec | client_security | 2.0.3 | - | - |
cpe:2.3:a:symantec:client_security:2.0.3:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.3_build_9.0.3.1000 | - | - |
cpe:2.3:a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3:*:*:*:*:*:*
|
| symantec | client_security | 2.0.4 | - | - |
cpe:2.3:a:symantec:client_security:2.0.4:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.5 | - | - |
cpe:2.3:a:symantec:client_security:2.0.5:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.5_build_1100 | - | - |
cpe:2.3:a:symantec:client_security:2.0.5_build_1100:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0.5_build_1100_mp1 | - | - |
cpe:2.3:a:symantec:client_security:2.0.5_build_1100_mp1:mr5:*:*:*:*:*:*
|
| symantec | client_security | 2.0.6 | - | - |
cpe:2.3:a:symantec:client_security:2.0.6:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0_scf_7.1 | - | - |
cpe:2.3:a:symantec:client_security:2.0_scf_7.1:*:*:*:*:*:*:*
|
| symantec | client_security | 2.0_stm_build_9.0.0.338 | - | - |
cpe:2.3:a:symantec:client_security:2.0_stm_build_9.0.0.338:*:*:*:*:*:*:*
|
| symantec | client_security | 2.1 | - | - |
cpe:2.3:a:symantec:client_security:2.1:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0 | - | - |
cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.0.359 | - | - |
cpe:2.3:a:symantec:client_security:3.0.0.359:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.1.1000 | - | - |
cpe:2.3:a:symantec:client_security:3.0.1.1000:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.1.1001 | - | - |
cpe:2.3:a:symantec:client_security:3.0.1.1001:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.1.1007 | - | - |
cpe:2.3:a:symantec:client_security:3.0.1.1007:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.1.1008 | - | - |
cpe:2.3:a:symantec:client_security:3.0.1.1008:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.1.1009 | - | - |
cpe:2.3:a:symantec:client_security:3.0.1.1009:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2000 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2000:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2001 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2001:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2002 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2002:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2010 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2010:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2011 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2011:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2020 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2020:*:*:*:*:*:*:*
|
| symantec | client_security | 3.0.2.2021 | - | - |
cpe:2.3:a:symantec:client_security:3.0.2.2021:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1 | - | - |
cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.0.396 | - | - |
cpe:2.3:a:symantec:client_security:3.1.0.396:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.0.401 | - | - |
cpe:2.3:a:symantec:client_security:3.1.0.401:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.394 | - | - |
cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.396 | - | - |
cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.400 | - | - |
cpe:2.3:a:symantec:client_security:3.1.400:*:*:*:*:*:*:*
|
| symantec | client_security | 3.1.401 | - | - |
cpe:2.3:a:symantec:client_security:3.1.401:*:*:*:*:*:*:*
|
| symantec | norton_antispam | 2005 | - | - |
cpe:2.3:a:symantec:norton_antispam:2005:*:*:*:*:*:*:*
|
| symantec | norton_antivirus | 3.0 | - | - |
cpe:2.3:a:symantec:norton_antivirus:3.0:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.0.338 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.0.338:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.1 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.1:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.1.1.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.1.1.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.1.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.1.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.2 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.2:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.2.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.2.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.3.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.3.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.4 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.4:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.5 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.5:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.5.1100 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.5.1100:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 9.0.6.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:9.0.6.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.1.1000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.1.1000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.1.1007 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.1.1007:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.1.1008 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.1.1008:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2000 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2000:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2001 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2001:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2002 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2002:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2010 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2010:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2011 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2011:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2020 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2020:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.0.2.2021 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.0.2.2021:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.4 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.4:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.4.4010 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.4.4010:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.394 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.394:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.396 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.396:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.400 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.400:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 10.1.401 | - | - |
cpe:2.3:a:symantec:norton_antivirus:10.1.401:*:corporate:*:*:*:*:*
|
| symantec | norton_antivirus | 2005 | - | - |
cpe:2.3:a:symantec:norton_antivirus:2005:*:*:*:*:*:*:*
|
| symantec | norton_antivirus | 2006 | - | - |
cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*
|
| symantec | norton_internet_security | 2005 | - | - |
cpe:2.3:a:symantec:norton_internet_security:2005:*:*:*:*:*:*:*
|
| symantec | norton_internet_security | 2006 | - | - |
cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
|
| symantec | norton_personal_firewall | * | - | - |
cpe:2.3:a:symantec:norton_personal_firewall:*:*:*:*:*:*:*:*
|
| symantec | norton_personal_firewall | 2005 | - | - |
cpe:2.3:a:symantec:norton_personal_firewall:2005:*:*:*:*:*:*:*
|
| symantec | norton_personal_firewall | 2006 | - | - |
cpe:2.3:a:symantec:norton_personal_firewall:2006:*:*:*:*:*:*:*
|
| symantec | norton_personal_firewall | 2006_9.1.0.33 | - | - |
cpe:2.3:a:symantec:norton_personal_firewall:2006_9.1.0.33:*:*:*:*:*:*:*
|
| symantec | norton_system_works | 2005 | - | - |
cpe:2.3:a:symantec:norton_system_works:2005:*:*:*:*:*:*:*
|
| symantec | norton_system_works | 2006 | - | - |
cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题
x_refsource_CONFIRM
cve.org
访问
cve.org
20070315 Norton Insufficient validation of 'SymTDI' driver input buffer
mailing-list
cve.org
访问
cve.org
20070315 Norton Insufficient validation of 'SymTDI' driver
mailing-list
cve.org
访问
cve.org
symantec-firewall-symtdi-dos(33003)
vdb-entry
cve.org
访问
cve.org
22977
vdb-entry
cve.org
访问
cve.org
35088
vdb-entry
cve.org
访问
cve.org
2438
third-party-advisory
cve.org
访问
cve.org
1018656
vdb-entry
cve.org
访问
cve.org
无标题
x_refsource_MISC
cve.org
访问
cve.org
ExploitDB EDB-29743
EXPLOIT
exploitdb
访问
exploitdb
Download Exploit EDB-29743
EXPLOIT
exploitdb
访问
exploitdb
CVE Reference: CVE-2007-1476
ADVISORY
cve.org
访问
cve.org
CVSS评分详情
1.9
LOW
CVSS向量:
AV:L/AC:M/Au:N/C:N/I:N/A:P
CVSS版本:
2.0
机密性
NONE
完整性
NONE
可用性
PARTIAL
时间信息
发布时间:
2007-03-16 21:00:00
修改时间:
2024-08-07 12:59:08
创建时间:
2025-11-11 15:32:42
更新时间:
2026-01-26 02:17:11
利用信息
此漏洞有可利用代码!
利用代码数量:
1
利用来源:
未知
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-1476 |
2025-11-11 15:17:51 | 2025-11-11 07:32:42 |
| NVD | nvd_CVE-2007-1476 |
2025-11-11 14:52:09 | 2025-11-11 07:41:28 |
| CNNVD | cnnvd_CNNVD-200703-393 |
2025-11-11 15:08:55 | 2025-11-11 07:49:15 |
| EXPLOITDB | exploitdb_EDB-29743 |
2025-11-11 15:05:51 | 2025-11-11 08:25:09 |
版本与语言
当前版本:
v4
主要语言:
EN
支持语言:
EN
ZH
其他标识符:
:
:
安全公告
暂无安全公告信息
变更历史
v4
EXPLOITDB
2025-11-11 16:25:09
references_count: 9 → 12; tags_count: 0 → 4; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- references_count: 9 -> 12
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3
CNNVD
2025-11-11 15:49:15
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-200703-393; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200703-393
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2
NVD
2025-11-11 15:41:28
severity: SeverityLevel.MEDIUM → SeverityLevel.LOW; cvss_score: 未提取 → 1.9; cvss_vector: NOT_EXTRACTED → AV:L/AC:M/Au:N/C:N/I:N/A:P; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 79; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.LOW
- cvss_score: 未提取 -> 1.9
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:M/Au:N/C:N/I:N/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 79
- data_sources: ['cve'] -> ['cve', 'nvd']