Vulnerabilities > CA > Arcserve Backup > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-10-13 CVE-2009-3588 Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
network
broadcom ca
4.3
2009-06-16 CVE-2009-1761 Improper Input Validation vulnerability in CA Arcserve Backup R12.0
The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.
network
low complexity
ca CWE-20
5.0
2008-10-14 CVE-2008-4400 Improper Input Validation vulnerability in multiple products
Unspecified vulnerability in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash of multiple services) via crafted authentication credentials, related to "insufficient validation."
network
low complexity
broadcom ca CWE-20
5.0
2008-10-14 CVE-2008-4399 Improper Input Validation vulnerability in multiple products
Unspecified vulnerability in the database engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request, related to "insufficient validation."
network
low complexity
broadcom ca CWE-20
5.0
2008-10-14 CVE-2008-4398 Improper Input Validation vulnerability in multiple products
Unspecified vulnerability in the tape engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request.
network
low complexity
broadcom ca CWE-20
5.0