Description
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via modified MIME data in a message.
Published: 2016-06-30
Score: 8.4 High
EPSS: 29.0% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Symantec Advanced Threat Protection Csapi Data Center Security Server Endpoint Protection Mail Security For Domino Mail Security For Microsoft Exchange Message Gateway Message Gateway For Service Providers Ngc Norton 360 Norton Antivirus Norton Bootable Removal Tool Norton Internet Security Norton Power Eraser Norton Security Norton Security With Backup Protection Engine Protection For Sharepoint Servers
cve-icon MITRE

Status: PUBLISHED

Assigner: symantec

Published:

Updated: 2024-08-06T00:03:34.389Z

Reserved: 2016-03-23T00:00:00.000Z

Link: CVE-2016-3644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-06-30T23:59:05.760

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-3644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses