Vulnerabilities > Broadcom > Brightstor Enterprise Backup

DATE CVE VULNERABILITY TITLE RISK
2007-10-13 CVE-2007-5332 Resource Management Errors vulnerability in Broadcom products
Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption.
network
low complexity
broadcom CWE-399
critical
10.0
2007-10-13 CVE-2007-5331 Code Injection vulnerability in multiple products
Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.
network
low complexity
broadcom ca CWE-94
critical
10.0
2007-10-13 CVE-2007-5330 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Broadcom products
The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.
network
low complexity
broadcom CWE-119
critical
10.0
2007-10-13 CVE-2007-5329 Resource Management Errors vulnerability in multiple products
Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.
network
low complexity
broadcom ca CWE-399
critical
10.0
2007-10-13 CVE-2007-5328 Permissions, Privileges, and Access Controls vulnerability in Broadcom products
The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."
network
low complexity
broadcom CWE-264
critical
10.0
2007-10-13 CVE-2007-5327 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Broadcom products
Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a long argument in the 0x10d opnum.
network
low complexity
broadcom CWE-119
critical
10.0
2007-10-13 CVE-2007-5326 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
broadcom ca CWE-119
critical
10.0
2007-10-13 CVE-2007-5325 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Broadcom products
Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
broadcom CWE-119
critical
10.0
2007-07-26 CVE-2007-3875 arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
network
broadcom ca
4.3
2007-07-18 CVE-2007-3825 Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.
network
broadcom ca
critical
9.3