Vulnerabilities > Broadcom > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-11-08 | CVE-2018-6433 | Improper Input Validation vulnerability in Broadcom Fabric Operating System A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system. | 2.1 |
2018-04-11 | CVE-2017-13678 | Cross-site Scripting vulnerability in Broadcom Advanced Secure Gateway and Symantec Proxysg Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. | 3.5 |
2017-05-11 | CVE-2016-9100 | Credentials Management vulnerability in Broadcom Advanced Secure Gateway and Symantec Proxysg Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. | 2.1 |
2016-06-29 | CVE-2015-8698 | Unspecified vulnerability in Broadcom Release Automation CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allows remote attackers to read arbitrary files or cause a denial of service via a request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 3.6 |
2015-04-08 | CVE-2015-2827 | Cross-site Scripting vulnerability in Broadcom Spectrum 9.2/9.3 Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2015-01-21 | CVE-2014-9224 | Cross-site Scripting vulnerability in multiple products Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2007-03-16 | CVE-2007-1448 | Unspecified vulnerability in Broadcom Brightstor Arcserve Backup The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function. | 2.1 |
2004-12-31 | CVE-2004-2436 | Unspecified vulnerability in Broadcom products Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | 2.1 |
2001-05-18 | CVE-2001-1346 | Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp. | 1.2 |