Ca Brightstor Arcserve Backup vulnerabilities

19 known vulnerabilities affecting ca/brightstor_arcserve_backup.

Total CVEs
19
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH6MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2008-3175CRITICALCVSS 10.0v11.0v11.12008-08-01
CVE-2008-3175 [CRITICAL] CWE-189 CVE-2008-3175: Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Lapto Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.
nvd
CVE-2008-2241CRITICALCVSS 10.0v11.0vr11.02008-05-21
CVE-2008-2241 [CRITICAL] CWE-22 CVE-2008-2241: Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writ
nvd
CVE-2008-2242HIGHCVSS 7.5v11.02008-05-21
CVE-2008-2242 [HIGH] CWE-119 CVE-2008-2242: Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1 Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function.
nvd
CVE-2007-4620CRITICALCVSS 9.0PoCv112008-04-07
CVE-2007-4620 [CRITICAL] CWE-119 CVE-2007-4620: Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert. Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafte
nvd
CVE-2007-5329CRITICALCVSS 10.0v112007-10-13
CVE-2007-5329 [CRITICAL] CWE-399 CVE-2007-5329: Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterp Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.
nvd
CVE-2007-5331CRITICALCVSS 10.0v112007-10-13
CVE-2007-5331 [CRITICAL] CWE-94 CVE-2007-5331: Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 thro Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.
nvd
CVE-2007-5326CRITICALCVSS 10.0v112007-10-13
CVE-2007-5326 [CRITICAL] CWE-119 CVE-2007-5326: Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2007-3875MEDIUMCVSS 4.3v112007-07-26
CVE-2007-3875 [MEDIUM] CVE-2007-3875: arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA produc arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
nvd
CVE-2007-3825CRITICALCVSS 9.3v112007-07-18
CVE-2007-3825 [CRITICAL] CVE-2007-3825: Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certa
nvd
CVE-2007-2863CRITICALCVSS 10.0v112007-06-06
CVE-2007-2863 [CRITICAL] CVE-2007-2863: Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (form Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.
nvd
CVE-2007-2772HIGHCVSS 7.8PoCv11.5.2.02007-05-21
CVE-2007-2772 [HIGH] CVE-2007-2772: (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Bac (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.
nvd
CVE-2007-2139CRITICALCVSS 10.0PoCv112007-04-25
CVE-2007-2139 [CRITICAL] CVE-2007-2139: Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) Br Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC stri
nvd
CVE-2007-1785HIGHCVSS 7.1PoCv112007-03-31
CVE-2007-1785 [HIGH] CVE-2007-1785: The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote a The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.
nvd
CVE-2006-6076CRITICALCVSS 10.0PoCv11v11.12006-11-24
CVE-2006-6076 [CRITICAL] CVE-2006-6076: Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARC Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.
nvd
CVE-2006-5143HIGHCVSS 7.5PoCv112006-10-10
CVE-2006-5143 [HIGH] CWE-119 CVE-2006-5143: Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; B Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (D
nvd
CVE-2005-3653CRITICALCVSS 10.0v112005-12-31
CVE-2005-3653 [CRITICAL] CWE-119 CVE-2005-3653: Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
nvd
CVE-2005-1272HIGHCVSS 7.5PoCv9.0.1v9.0_1+2 more2005-08-05
CVE-2005-1272 [HIGH] CVE-2005-1272: Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Back Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.
nvd
CVE-2005-1693CRITICALCVSS 10.0v11.12005-05-24
CVE-2005-1693 [CRITICAL] CVE-2005-1693: Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows r
nvd
CVE-2005-1018HIGHCVSS 7.5PoCv11.12005-05-02
CVE-2005-1018 [HIGH] CVE-2005-1018: Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.
nvd