Vulnerabilities > CA

DATE CVE VULNERABILITY TITLE RISK
2010-04-07 CVE-2010-1221 Improper Authentication vulnerability in CA products
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
network
low complexity
ca CWE-287
5.0
2010-02-24 CVE-2010-0640 Cross-Site Scripting vulnerability in CA Ehealth Performance Manager 6.0/6.1/6.2
Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.
network
high complexity
ca CWE-79
2.6
2009-12-09 CVE-2009-4149 Cross-Site Scripting vulnerability in CA Service Desk 12.1
Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
network
ca CWE-79
4.3
2009-12-08 CVE-2009-4225 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in CA Etrust Pestpatrole Ppctl.Dll Activex 5.6.7.9
Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method.
network
ca CWE-119
critical
9.3
2009-10-13 CVE-2009-3588 Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
network
broadcom ca
4.3
2009-10-13 CVE-2009-3587 Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.
network
broadcom ca
critical
9.3
2009-08-19 CVE-2009-2740 Resource Management Errors vulnerability in CA Host-Based Intrusion Prevention System 8.1
kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet.
network
low complexity
ca CWE-399
5.0
2009-08-19 CVE-2009-0682 Improper Input Validation vulnerability in CA Internet Security Suite 10.0.0.217/9.0.0.184
vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.
local
low complexity
ca CWE-20
2.1
2009-08-10 CVE-2009-2026 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in CA products
Stack-based buffer overflow in a token searching function in the dtscore library in Data Transport Services in CA Software Delivery r11.2 C1, C2, C3, and SP4; Unicenter Software Delivery 4.0 C3; CA Advantage Data Transport 3.0 C1; and CA IT Client Manager r12 allows remote attackers to execute arbitrary code via crafted data.
network
low complexity
ca CWE-119
critical
10.0
2009-06-16 CVE-2009-1761 Improper Input Validation vulnerability in CA Arcserve Backup R12.0
The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.
network
low complexity
ca CWE-20
5.0