CVE-2003-1451
CVE-2003-1451 is a medium-severity vulnerability in Symantec Norton Antivirus with a CVSS 2.0 base score of 6.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.4)
- EPSS exploit prediction: 3% (88th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Symantec Norton Antivirus
- Published:
- Last modified:
Description
Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.
Frequently asked questions
- What is CVE-2003-1451?
- Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.
- How severe is CVE-2003-1451?
- CVE-2003-1451 has a CVSS 2.0 base score of 6.4, rated medium severity.
- Is CVE-2003-1451 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (88th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2003-1451?
- CVE-2003-1451 affects Symantec Norton Antivirus. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2003-1451?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2003-1451 published?
- CVE-2003-1451 was published on 2003-12-31 and last updated on 2026-06-16.
References
- http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-02/0233.html
- http://www.lac.co.jp/security/english/snsadv_e/61_e.html
- http://www.securityfocus.com/bid/6886
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11365
Affected products (1)
- cpe:2.3:a:symantec:norton_antivirus:2002:*:*:*:*:*:*:*
More vulnerabilities in Symantec Norton Antivirus
- CVE-2006-6490 — Critical (CVSS 10.0): Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX…
- CVE-2006-2630 — Critical (CVSS 10.0): Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute…
- CVE-2005-2017 — Critical (CVSS 10.0): Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which…
- CVE-2004-0487 — Critical (CVSS 10.0): A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service…
- CVE-2000-0793 — Critical (CVSS 10.0): Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after…
- CVE-2016-3645 — Critical (CVSS 9.8): Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP);…
All CVEs affecting Symantec Norton Antivirus →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-77946 — Critical (CVSS 10.0): A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function…
- CVE-2026-76008 — Critical (CVSS 10.0): A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file…
- CVE-2026-75784 — Critical (CVSS 10.0): A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of…
- CVE-2026-74843 — Critical (CVSS 10.0): A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function…
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-2778 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in…