CVE-2007-1476
CVE-2007-1476 is a low-severity vulnerability in Symantec Client Security with a CVSS 2.0 base score of 1.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Low (CVSS 2.0 base score 1.9)
- EPSS exploit prediction: 1% (56th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Symantec Client Security
- Published:
- Last modified:
Description
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.
Frequently asked questions
- What is CVE-2007-1476?
- The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.
- How severe is CVE-2007-1476?
- CVE-2007-1476 has a CVSS 2.0 base score of 1.9, rated low severity.
- Is CVE-2007-1476 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (56th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2007-1476?
- CVE-2007-1476 primarily affects Symantec Client Security. In total, 84 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2007-1476?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2007-1476 published?
- CVE-2007-1476 was published on 2007-03-16 and last updated on 2026-06-16.
References
- http://marc.info/?l=full-disclosure&m=117396596027148&w=2
- http://osvdb.org/35088
- http://securityreason.com/securityalert/2438
- http://securitytracker.com/id?1018656
- http://www.matousec.com/info/advisories/Norton-Insufficient-validation-of-SymTDI-driver-input-buffer.php
- http://www.securityfocus.com/archive/1/462926/100/0/threaded
- http://www.securityfocus.com/bid/22977
- http://www.symantec.com/avcenter/security/Content/2007.09.05.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33003
Affected products (84)
- cpe:2.3:a:symantec:client_security:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0:*:scf_7.1:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0:build_9.0.0.338:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0:build_9.0.0.338:stm:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.4:mr4_build1000:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.5_build_1100:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.5_build_1100_mp1:mr5:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0.6:mr6:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0_scf_7.1:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.0_stm_build_9.0.0.338:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.0.359:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.1.1000:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.1.1001:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.1.1007:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.1.1008:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.1.1009:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2000:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2001:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2002:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2010:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2011:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2020:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.0.2.2021:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.1.0.396:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.1.0.401:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:*
More vulnerabilities in Symantec Client Security
- CVE-2010-0108 — Critical (CVSS 10.0): Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec…
- CVE-2009-1429 — Critical (CVSS 10.0): The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System…
- CVE-2006-2630 — Critical (CVSS 10.0): Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute…
- CVE-2004-0444 — Critical (CVSS 10.0): Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton…
- CVE-2010-0107 — Critical (CVSS 9.3): Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus,…
- CVE-2009-1431 — Critical (CVSS 9.3): XFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in…
All CVEs affecting Symantec Client Security →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →