Vulnerabilities > Symantec Veritas > Backup Exec

DATE CVE VULNERABILITY TITLE RISK
2006-08-14 CVE-2006-4128 Heap Overflow vulnerability in Symantec Backup Exec
Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and Backup Exec for Windows Server and Remote Agent 9.1 (build 9.1.4691), 10.0 (builds 10.0.5484 and 10.0.5520), and 10.1 (build 10.1.5629) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RPC message.
network
low complexity
symantec-veritas
6.5
2006-03-19 CVE-2006-1298 Remote Format String vulnerability in Veritas Backup Exec Media Server BEngine Service Job Log
Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev.
network
high complexity
symantec-veritas
4.6
2006-03-19 CVE-2006-1297 Remote Denial of Service vulnerability in Symantec Veritas Backup Exec and Backup Exec Remote Agent
Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors."
network
low complexity
symantec-veritas
5.0
2005-08-17 CVE-2005-2611 Unspecified vulnerability in Symantec Veritas Backup Exec, Backup Exec Remote Agent and Netbackup
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.
network
low complexity
symantec-veritas
critical
10.0
2005-08-02 CVE-2005-2079 Remote Heap Overflow vulnerability in Veritas Backup Exec Admin Plus Pack Option
Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.
network
low complexity
symantec-veritas
7.5
2005-06-29 CVE-2005-2080 Remote Agent for Windows Servers Privilege Escalation vulnerability in Veritas Backup Exec
Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.
network
low complexity
symantec-veritas
7.5
2005-06-28 CVE-2005-2051 Remote Buffer Overflow vulnerability in Veritas Backup Exec Web Administration Console
Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev.
network
low complexity
symantec-veritas
7.5
2005-06-23 CVE-2005-0771 Unspecified vulnerability in Symantec Veritas Backup Exec
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106.
network
low complexity
symantec-veritas
critical
10.0
2005-06-18 CVE-2005-0773 Remote Agent for Windows Servers Authentication Buffer Overflow vulnerability in Veritas Backup Exec
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.
network
low complexity
symantec-veritas
7.5
2005-01-10 CVE-2004-1172 Remote Buffer Overflow vulnerability in VERITAS Backup Exec Agent Browser
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.
network
low complexity
symantec-veritas
critical
10.0