Vulnerabilities > Broadcom > Brightstor Arcserve Backup
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-08-01 | CVE-2008-3175 | Numeric Errors vulnerability in multiple products Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow. | 10.0 |
2008-05-21 | CVE-2008-2242 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function. | 7.5 |
2008-05-21 | CVE-2008-2241 | Path Traversal vulnerability in multiple products Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. | 10.0 |
2008-04-27 | CVE-2008-1979 | Numeric Errors vulnerability in Broadcom Brightstor Arcserve Backup The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read. | 5.0 |
2008-04-07 | CVE-2007-4620 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests. | 9.0 |
2007-10-13 | CVE-2007-5332 | Resource Management Errors vulnerability in Broadcom products Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption. | 10.0 |
2007-10-13 | CVE-2007-5331 | Code Injection vulnerability in multiple products Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers. | 10.0 |
2007-10-13 | CVE-2007-5330 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Broadcom products The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers. | 10.0 |
2007-10-13 | CVE-2007-5329 | Resource Management Errors vulnerability in multiple products Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption. | 10.0 |
2007-10-13 | CVE-2007-5328 | Permissions, Privileges, and Access Controls vulnerability in Broadcom products The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure." | 10.0 |