Vulnerabilities > EMC

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-3658 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in EMC Legato Networker
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
network
low complexity
emc CWE-119
7.5
2005-08-23 CVE-2005-0359 Multiple vulnerability in EMC Legato Networker
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
network
low complexity
emc sun
6.4
2005-08-23 CVE-2005-0358 Multiple vulnerability in EMC Legato Networker
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
network
low complexity
emc sun
7.5
2005-08-23 CVE-2005-0357 Multiple vulnerability in EMC Legato Networker
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
network
low complexity
emc sun
7.5
2005-08-16 CVE-2005-2358 Directory Traversal And Information Disclosure vulnerability in EMC Navisphere Manager
EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).
network
low complexity
emc
5.0
2005-08-16 CVE-2005-2357 Directory Traversal And Information Disclosure vulnerability in EMC Navisphere Manager
Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a ..
network
low complexity
emc
5.0
2005-07-11 CVE-2005-2185 Remote Security vulnerability in Eroom
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.
network
low complexity
emc
7.5
2005-07-11 CVE-2005-2184 Remote Security vulnerability in Eroom
eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.
network
low complexity
emc
7.5
2002-03-25 CVE-2002-0114 Unspecified vulnerability in EMC Networker 6.1
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file.
local
low complexity
emc
4.6
2002-03-25 CVE-2002-0113 Unspecified vulnerability in EMC Networker 6.1
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges.
local
low complexity
emc
4.6