Symantec Norton AntiSpam has been reported prone to a remotely exploitable buffer overrun vulnerability.
This issue exists in the SymSpamHelper Class ActiveX component, which could be invoked from a web page or HTML e-mail with malformed parameters sufficient to trigger the condition. This could be exploited to execute arbitrary code with the privileges of the client user.
Vendor Status:
Symantec as issued an update for this vulnerablity