Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Project Portfolio Management MEDIUM 6.1
CVE-2018-13825

Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below,…

Fix: after 14.3
Fix from $1,600 2018-08-30
Project Portfolio Management HIGH 7.5
CVE-2018-13822

Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensi…

Fix: after 14.3
Fix from $1,950 2018-08-30
Ca Api Developer Portal MEDIUM 6.1
CVE-2018-6590

CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerability.

Fix: 4.2.5.3+
Fix from $1,600 2018-08-03
Tcpreplay HIGH 7.5
CVE-2018-13112

get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application …

No fix yet
Fix from $1,950 2018-07-03
Privileged Access Manager CRITICAL 9.8
CVE-2015-4664EPSS 21%

An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

Fix: after 2.4.4.4
Fix from $2,300 2018-06-18
Privileged Access Manager CRITICAL 9.8
CVE-2018-9021EPSS 10%

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with s…

Fix: after 2.8.2
Fix from $2,300 2018-06-18
Privileged Access Manager CRITICAL 9.8
CVE-2018-9022EPSS 13%

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or command…

Fix: after 2.8.2
Fix from $2,300 2018-06-18
Privileged Access Manager CRITICAL 9.8
CVE-2018-9029

An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

Fix: 3.0.0+
Fix from $2,300 2018-06-18
Privileged Access Manager HIGH 8.8
CVE-2018-9023

An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially cr…

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Privileged Access Manager HIGH 7.5
CVE-2018-9025

An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Privileged Access Manager HIGH 7.5
CVE-2018-9026

A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Privileged Access Manager HIGH 7.5
CVE-2018-9028

Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Privileged Access Manager MEDIUM 5.3
CVE-2018-9024

An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

Fix: 3.0.0+
Fix from $1,600 2018-06-18
Advanced Secure Gateway CRITICAL 9.8
CVE-2018-5241

Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The …

Mitigation only
Fix from $2,300 2018-05-29
Ssl Visibility Appliance MEDIUM 5.9
CVE-2017-15533

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher O…

Mitigation only
Fix from $1,600 2018-05-17
Symantec Intelligencecenter MEDIUM 5.9
CVE-2017-18268

Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a…

Mitigation only
Fix from $1,600 2018-05-17
Advanced Secure Gateway HIGH 7.5
CVE-2017-13677EPSS 5%

Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafte…

Fix: 6.5.10.8 / 6.6.5.14+
Fix from $1,950 2018-04-11
Advanced Secure Gateway MEDIUM 6.8
CVE-2016-10258

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administr…

Fix: 6.5.10.8 / 6.6.5.14+
Fix from $1,600 2018-04-11
Fabric Operating System MEDIUM 6.5
CVE-2017-6227

A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could…

Fix: 7.4.2b+
Fix from $1,600 2018-02-08
Fabric Operating System MEDIUM 6.1
CVE-2017-6225

Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) …

Fix: 7.4.2b+
Fix from $1,600 2018-02-08
Symantec Proxysg MEDIUM 6.1
CVE-2016-10256

The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A r…

Fix: 6.5.10.6 / 6.7.2.1+
Fix from $1,600 2018-01-10
Advanced Secure Gateway MEDIUM 6.1
CVE-2016-10257

The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6, and ProxySG 6.7 (prior to 6…

Fix: 6.5.10.6 / 6.7.2.1+
Fix from $1,600 2018-01-10
Bcm4355c0 Firmware HIGH 7.5
CVE-2017-11122

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to IC…

Fix: after 10.3.3
Fix from $1,950 2017-10-04
Bcm4355c0 Firmware CRITICAL 9.8
CVE-2017-11120EPSS 9%

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an intern…

Fix: 11.0+
Fix from $2,300 2017-09-28
Bcm4355c0 Firmware CRITICAL 9.8
CVE-2017-11121

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transition frames can potentially t…

Fix: 11.0+
Fix from $2,300 2017-09-28
Tcpreplay HIGH 7.8
CVE-2017-14266

tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.

No fix yet
Fix from $1,950 2017-09-12
Bcm43xx Wi Fi Chipset Firmware CRITICAL 9.8
CVE-2017-9417EPSS 48%

Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

Mitigation only
Fix from $2,300 2017-06-04
Advanced Secure Gateway HIGH 7.8
CVE-2016-9100

Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13,…

Fix: 6.5.10.6 / 6.6.5.13+
Fix from $1,950 2017-05-11
Advanced Secure Gateway HIGH 7.2
CVE-2016-9097

The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6…

Mitigation only
Fix from $1,950 2017-05-11
Advanced Secure Gateway MEDIUM 6.1
CVE-2016-9099

Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 ar…

Fix: 6.5.10.6 / 6.7.2.1+
Fix from $1,600 2017-05-11