Symantec Backup Exec For Windows Server vulnerabilities
4 known vulnerabilities affecting symantec/backup_exec_for_windows_server.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2008-5407CRITICALCVSS 9.4v11dv12.0+1 more2008-12-10
CVE-2008-5407 [CRITICAL] CWE-287 CVE-2008-5407: Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backu
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors.
nvd
CVE-2008-5408CRITICALCVSS 9.0v11dv12.0+1 more2008-12-10
CVE-2008-5408 [CRITICAL] CVE-2008-5408: Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (ak
Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote
nvd
CVE-2007-6016CRITICALCVSS 9.3PoCv11dv12.02008-02-29
CVE-2007-6016 [CRITICAL] CWE-119 CVE-2007-6016: Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalenda
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWT
nvd
CVE-2007-6017MEDIUMCVSS 5.1v11dv12.02008-02-29
CVE-2007-6017 [MEDIUM] CWE-20 CVE-2007-6017: The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the M
The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary fi
nvd