peter bassill · operator
$ cve CVE-2007-1689 JSON

CVE-2007-1689 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 65% (pctl 99)

Patch early

A public exploit exists.

Description

Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS65.01% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-16
Last modified2026-06-16

Affected (2)

VendorProduct
symantecnorton internet security
symantecnorton personal firewall

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD