← Back

CVE-2006-3072

nvd nist
Published: Jun 19, 2006Modified: Apr 16, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted "rule definitions", which produces dangerous Java code during M4 transformation.

Affected (30)

1 product
Security Information Manager
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 4.0.2.10
Version 4.0.2.11
Version 4.0.2.12
Version 4.0.2.13
Version 4.0.2.14
Version 4.0.2.15
Version 4.0.2.16
Version 4.0.2.17
Version 4.0.2.18
Version 4.0.2.19
Version 4.0.2.1
Version 4.0.2.20
Version 4.0.2.21
Version 4.0.2.22
Version 4.0.2.23
Version 4.0.2.24
Version 4.0.2.25
Version 4.0.2.26
Version 4.0.2.27
Version 4.0.2.28
Version 4.0.2.29
Version 4.0.2.2
Version 4.0.2.3
Version 4.0.2.4
Version 4.0.2.5
Version 4.0.2.6
Version 4.0.2.7
Version 4.0.2.8
Version 4.0.2.9
Version 4.0.2

References (12)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.