Vulnerabilities > EMC > High

DATE CVE VULNERABILITY TITLE RISK
2008-02-21 CVE-2007-6426 Buffer Errors vulnerability in EMC Replistor 6.2Sp2
Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via crafted compressed data.
network
low complexity
emc CWE-119
7.8
2007-04-30 CVE-2006-7199 Remote Security vulnerability in Rsa Security Sitekey
EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server.
network
emc
8.5
2006-05-16 CVE-2006-2391 Remote Buffer Overflow vulnerability in EMC Dantz Retrospect Backup Client
Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet to port 497.
network
low complexity
emc
7.5
2006-05-03 CVE-2006-2154 Local Privilege Escalation vulnerability in EMC Dantz Retrospect Backup Server
EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the File>Open dialog.
local
low complexity
emc
7.2
2005-12-31 CVE-2005-3658 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in EMC Legato Networker
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
network
low complexity
emc CWE-119
7.5
2005-08-23 CVE-2005-0358 Multiple vulnerability in EMC Legato Networker
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
network
low complexity
emc sun
7.5
2005-08-23 CVE-2005-0357 Multiple vulnerability in EMC Legato Networker
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
network
low complexity
emc sun
7.5
2005-07-11 CVE-2005-2185 Remote Security vulnerability in Eroom
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.
network
low complexity
emc
7.5
2005-07-11 CVE-2005-2184 Remote Security vulnerability in Eroom
eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.
network
low complexity
emc
7.5
2001-11-21 CVE-2001-0910 Authentication vulnerability in EMC Networker 6.0
Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup.
network
low complexity
emc
7.5