Vulnerabilities > Broadcom > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-01-23 CVE-2007-0449 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Broadcom products
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.
network
low complexity
broadcom CWE-119
critical
10.0
2007-01-16 CVE-2006-5172 Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe String Handling Overflow," a different vulnerability than CVE-2006-5171.
network
low complexity
broadcom ca
critical
10.0
2007-01-16 CVE-2006-5171 Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe Overflow," a different vulnerability than CVE-2006-5172.
network
low complexity
broadcom ca
critical
10.0
2006-12-31 CVE-2006-6917 Unspecified vulnerability in Broadcom Brightstor Arcserve Backup Server 11.5
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.
network
low complexity
broadcom
critical
10.0
2006-12-31 CVE-2006-6905 Remote Security vulnerability in Widcomm Bluetooth
Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
network
low complexity
broadcom
critical
10.0
2006-11-24 CVE-2006-6076 Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.
network
low complexity
broadcom ca
critical
10.0
2006-08-04 CVE-2006-3977 Unspecified vulnerability in Broadcom Etrust Antivirus Webscan 1.1.0.1045/1.1.0.1047
Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 has unknown impact and remote attackers related to "improper processing of outdated WebScan components."
network
broadcom
critical
9.3
2006-08-04 CVE-2006-3976 Unspecified vulnerability in Broadcom Etrust Antivirus Webscan 1.1.0.1045/1.1.0.1047
Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 allows remote attackers to install arbitrary files.
network
broadcom
critical
9.3
2005-12-31 CVE-2005-3653 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
network
low complexity
broadcom ca CWE-119
critical
10.0
2005-08-23 CVE-2005-2669 Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.
network
low complexity
broadcom ca
critical
10.0