Back to Database
Status published
High
CVE-2007-3951
Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers...
Vulnerability Description
Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3951
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/37982
- http://www.securityfocus.com/bid/25003
- http://osvdb.org/37983
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35561
- http://www.vupen.com/english/advisories/2007/2619
- http://www.securityfocus.com/archive/1/474423/100/0/threaded
- http://www.nruns.com/security_advisory_norman_antivirus_lzh_buffer_overflow.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35559
- http://secunia.com/advisories/26178
- http://www.nruns.com/security_advisory_Norman_all_ace_buffer_overflow.php
- http://www.securityfocus.com/bid/25015
- http://www.securitytracker.com/id?1018438
- http://www.securityfocus.com/archive/1/474432/100/0/threaded
- http://securityreason.com/securityalert/2912
More from norman
View All →CVE-2020-8508
nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call...
Critical
9.8
CVE-2014-0816
Unspecified vulnerability in Norman Security Suite 10.1 and earlier allows...
High
7.2
CVE-2010-5167
Race condition in Norman Security Suite PRO 8.0 on Windows...
Medium
6.2
CVE-2008-5535
Norman Antivirus 5.80.02, when Internet Explorer 6 or 7 is...
Critical
9.3
CVE-2007-4648
The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses...
High
7.2
Affected Vendor
norman
View all reports →Affected Software
norman virus control
Vulnerable Versions:
0
Timeline
Official Publish:
July 24th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.