Broadcom Brightstor Enterprise Backup vulnerabilities

19 known vulnerabilities affecting broadcom/brightstor_enterprise_backup.

Total CVEs
19
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH6MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2007-5328CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5328 [CRITICAL] CWE-264 CVE-2007-5328: The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."
nvd
CVE-2007-5325CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5325 [CRITICAL] CWE-119 CVE-2007-5325: Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe Bac Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2007-5330CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5330 [CRITICAL] CWE-119 CVE-2007-5330: The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1 The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.
nvd
CVE-2007-5332CRITICALCVSS 10.0PoCv10.52007-10-13
CVE-2007-5332 [CRITICAL] CWE-399 CVE-2007-5332: Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe Bac Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, have unknown impact and attack vectors related to memory corruption.
nvd
CVE-2007-5329CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5329 [CRITICAL] CWE-399 CVE-2007-5329: Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterp Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.
nvd
CVE-2007-5327CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5327 [CRITICAL] CWE-119 CVE-2007-5327: Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightS Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a long argument in the 0x10d opnum.
nvd
CVE-2007-5331CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5331 [CRITICAL] CWE-94 CVE-2007-5331: Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 thro Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.
nvd
CVE-2007-5326CRITICALCVSS 10.0v10.52007-10-13
CVE-2007-5326 [CRITICAL] CWE-119 CVE-2007-5326: Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2007-3875MEDIUMCVSS 4.3v10.52007-07-26
CVE-2007-3875 [MEDIUM] CVE-2007-3875: arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA produc arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
nvd
CVE-2007-3825CRITICALCVSS 9.3v10.52007-07-18
CVE-2007-3825 [CRITICAL] CVE-2007-3825: Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certa
nvd
CVE-2007-2863CRITICALCVSS 10.0v10.52007-06-06
CVE-2007-2863 [CRITICAL] CVE-2007-2863: Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (form Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.
nvd
CVE-2006-5172CRITICALCVSS 10.0v10.52007-01-16
CVE-2006-5172 [CRITICAL] CVE-2006-5172: Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brights Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe String Handling Overflow," a different vulnerability than CVE-2006-5
nvd
CVE-2006-5171CRITICALCVSS 10.0v10.52007-01-16
CVE-2006-5171 [CRITICAL] CVE-2006-5171: Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brights Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe Overflow," a different vulnerability than CVE-2006-5172.
nvd
CVE-2007-0168HIGHCVSS 7.5PoCv10.52007-01-11
CVE-2007-0168 [HIGH] CVE-2007-0168: The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, En The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.
nvd
CVE-2007-0169HIGHCVSS 7.5PoCv10.52007-01-11
CVE-2007-0169 [HIGH] CWE-119 CVE-2007-0169: Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Eng
nvd
CVE-2006-6379HIGHCVSS 7.5PoCv10.52006-12-10
CVE-2006-6379 [HIGH] CVE-2006-6379: Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCser Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2006-5143HIGHCVSS 7.5PoCv10.52006-10-10
CVE-2006-5143 [HIGH] CWE-119 CVE-2006-5143: Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; B Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (D
nvd
CVE-2005-2535HIGHCVSS 7.5PoCv10v10.0+1 more2005-08-10
CVE-2005-2535 [HIGH] CVE-2005-2535: Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remot Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.
nvd
CVE-2005-1272HIGHCVSS 7.5PoCv10.0v10.52005-08-05
CVE-2005-1272 [HIGH] CVE-2005-1272: Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Back Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.
nvd