Vulnerability index

Browse CVEs

300 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Networker Client HIGH 7.8
CVE-2008-6219

nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Stor…

Fix: after 7.3.2
Fix from $1,950 2009-02-20
Autostart HIGH 10.0
CVE-2009-0311

The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted v…

Fix: after 5.3
Fix from $1,950 2009-01-27
Control Center HIGH 10.0
CVE-2008-5419EPSS 8%

Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attackers to e…

Mitigation only
Fix from $1,950 2008-12-10
Control Center HIGH 7.8
CVE-2008-5420

The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which …

Fix: after 6.0
Fix from $1,950 2008-12-10
Centera Universal Access HIGH 7.5
CVE-2008-3370

SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2008-07-30
Dantz Retrospect Backup Server MEDIUM 5.0
CVE-2008-3288

The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-depend…

Patch available
Fix from $1,600 2008-07-24
Diskxtender CRITICAL 9.8
CVE-2008-0961

EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.

Mitigation only
Fix from $2,300 2008-04-14
Diskxtender HIGH 9.0
CVE-2008-0962

Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a…

Mitigation only
Fix from $1,950 2008-04-14
Diskxtender HIGH 9.0
CVE-2008-0963

Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message t…

Mitigation only
Fix from $1,950 2008-04-14
Replistor HIGH 7.8
CVE-2007-6426

Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via cr…

Mitigation only
Fix from $1,950 2008-02-21
Documentum Administrator HIGH 10.0
CVE-2008-0656

Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to ove…

Mitigation only
Fix from $1,950 2008-02-07
Replistor HIGH 10.0
CVE-2007-5323EPSS 5%

The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor to creat…

Mitigation only
Fix from $1,950 2007-10-11
Legato Networker HIGH 9.3
CVE-2007-3618EPSS 7%

Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute ar…

Patch available
Fix from $1,950 2007-08-21
VMware HIGH 9.3
CVE-2007-4155EPSS 10%

Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary loc…

No fix yet
Fix from $1,950 2007-08-03
Rsa Security Sitekey HIGH 9.3
CVE-2006-7201

EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared object), which might allow remot…

Mitigation only
Fix from $1,950 2007-04-30
Rsa Security Sitekey HIGH 9.0
CVE-2006-7200

EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier fo…

Mitigation only
Fix from $1,950 2007-04-30
Rsa Security Sitekey HIGH 8.5
CVE-2006-7199

EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled s…

Mitigation only
Fix from $1,950 2007-04-30
Networker HIGH 10.0
CVE-2006-3892

The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote …

Patch available
Fix from $1,950 2007-03-02
Retrospect Client HIGH 7.5
CVE-2006-2391EPSS 8%

Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …

Patch available
Fix from $1,950 2006-05-16
Retrospect HIGH 7.2
CVE-2006-2154

EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allo…

Fix: after 7.5
Fix from $1,950 2006-05-03
Legato Networker HIGH 7.5
CVE-2005-3658EPSS 5%

Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Sols…

Patch available
Fix from $1,950 2005-12-31
Legato Networker MEDIUM 5.0
CVE-2005-3659

nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.…

Patch available
Fix from $1,600 2005-12-31
Legato Networker HIGH 7.5
CVE-2005-0357

EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies …

Patch available
Fix from $1,950 2005-08-23
Legato Networker HIGH 7.5
CVE-2005-0358

EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which…

Patch available
Fix from $1,950 2005-08-23
Legato Networker MEDIUM 6.4
CVE-2005-0359

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict acce…

Patch available
Fix from $1,600 2005-08-23
Navisphere Manager MEDIUM 5.0
CVE-2005-2357

Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Mitigation only
Fix from $1,600 2005-08-16
Navisphere Manager MEDIUM 5.0
CVE-2005-2358

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (traili…

Patch available
Fix from $1,600 2005-08-16
Eroom HIGH 7.5
CVE-2005-2184

eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.

Mitigation only
Fix from $1,950 2005-07-11
Eroom HIGH 7.5
CVE-2005-2185

eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.

Mitigation only
Fix from $1,950 2005-07-11
Networker HIGH 7.5
CVE-2001-0910

Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admi…

Mitigation only
Fix from $1,950 2001-11-21