Vulnerabilities > RSA > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-05-04 CVE-2020-5332 OS Command Injection vulnerability in RSA Archer
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability.
network
low complexity
rsa CWE-78
critical
9.0
2012-03-20 CVE-2012-0402 Credentials Management vulnerability in RSA Envision 4.0/4.1
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.
network
rsa CWE-255
critical
9.3
2011-12-17 CVE-2011-4141 Unspecified vulnerability in RSA Securid 4.1/4.1.0.545
Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file.
network
rsa
critical
9.3
2007-07-15 CVE-2007-2417 Buffer Overflow vulnerability in Progress and OpenEdge _mprosrv
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets.
network
low complexity
rsa progress
critical
10.0
1999-12-01 CVE-1999-0834 Unspecified vulnerability in RSA Rsaref 2.0
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
network
low complexity
rsa
critical
10.0