Vulnerabilities > EMC > Avamar > High

DATE CVE VULNERABILITY TITLE RISK
2013-01-21 CVE-2012-2291 Permissions, Privileges, and Access Controls vulnerability in EMC Avamar and Avamar Plugin
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
local
low complexity
emc apple hp CWE-264
7.2
2011-09-19 CVE-2011-1740 Permissions, Privileges, and Access Controls vulnerability in EMC Avamar
EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.
low complexity
emc CWE-264
7.7
2011-03-16 CVE-2011-0648 Remote Privilege Escalation vulnerability in EMC Avamar (CVE-2011-0648)
Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.
network
emc
8.5
2010-05-28 CVE-2010-1919 Denial of Service vulnerability in EMC Avamar 4.0/4.1/5.0
Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP.
network
emc
7.1