Vulnerabilities > CA > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-12-11 CVE-2008-5415 The LDBserver service in the server in CA ARCserve Backup 11.1 through 12.0 on Windows allows remote attackers to execute arbitrary code via a handle_t argument to an RPC endpoint in which the argument refers to an incompatible procedure.
network
low complexity
broadcom ca
critical
10.0
2008-10-14 CVE-2008-4397 Improper Input Validation vulnerability in multiple products
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a ..
network
low complexity
broadcom ca CWE-20
critical
10.0
2008-08-01 CVE-2008-3175 Numeric Errors vulnerability in multiple products
Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.
network
low complexity
broadcom ca CWE-189
critical
10.0
2008-06-04 CVE-2008-2541 Buffer Errors vulnerability in CA Etrust Secure Content Manager 8.0
Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
network
low complexity
ca CWE-119
critical
10.0
2008-06-02 CVE-2008-2511 Path Traversal vulnerability in CA Internet Security Suite Plus 2008
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a ..
network
ca CWE-22
critical
9.3
2008-05-21 CVE-2008-2241 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages.
network
low complexity
broadcom ca CWE-22
critical
10.0
2008-04-07 CVE-2007-4620 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.
network
low complexity
broadcom ca CWE-119
critical
9.0
2007-10-13 CVE-2007-5331 Code Injection vulnerability in multiple products
Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.
network
low complexity
broadcom ca CWE-94
critical
10.0
2007-10-13 CVE-2007-5329 Resource Management Errors vulnerability in multiple products
Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.
network
low complexity
broadcom ca CWE-399
critical
10.0
2007-10-13 CVE-2007-5326 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
broadcom ca CWE-119
critical
10.0