Unrated severityNVD Advisory· Published Nov 14, 2012· Updated Apr 29, 2026
CVE-2012-4953
CVE-2012-4953
Description
The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file.
Affected products
10cpe:2.3:a:symantec:antivirus:10.1.0:-:corporate:*:*:*:*:*+ 6 more
- cpe:2.3:a:symantec:antivirus:10.1.0:-:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.4:*:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.5:*:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.6:*:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.7:*:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.8:*:corporate:*:*:*:*:*
- cpe:2.3:a:symantec:antivirus:10.1.9:*:corporate:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:symantec:endpoint_protection:12.0:-:small_business:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.