Vulnerability index

Browse CVEs

300 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2016-0903 Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remot… Avamar Server after 7.3.0 Fix from $2,3002016-09-21 MEDIUM 6.1 CVE-2016-6643 Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified … Vipr Srm after 3.7.1 Fix from $1,6002016-09-18 MEDIUM 6.1 CVE-2016-6642 Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators f… Vipr Srm after 3.7.1 Fix from $1,6002016-09-18 HIGH 7.6 CVE-2016-6641 Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via un… Vipr Srm after 3.7.1 Fix from $1,9502016-09-18 CRITICAL 9.8 CVE-2016-0922 EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain acce… Vipr Srm after 3.7.1 Fix from $2,3002016-09-18 MEDIUM 5.3 CVE-2016-6644 EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of … Documentum D2 after 4.6 Fix from $1,6002016-09-17 HIGH 8.1 CVE-2016-0915 The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users… Authentication Manager Prime Mitigation only Fix from $1,9502016-08-22 HIGH 8.8 CVE-2016-0906 The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remo… Avamar after 7.2.1 Fix from $1,9502016-07-06 MEDIUM 6.3 CVE-2016-0899 EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential informatio… Rsa Archer Egrc Mitigation only Fix from $1,6002016-07-04 MEDIUM 6.3 CVE-2016-0914 EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.… Documentum Administrator Mitigation only Fix from $1,6002016-06-23 CRITICAL 9.8 CVE-2016-0916EPSS 8% EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary… Networker 8.2.2.6 / 9.0.0.6+ Fix from $2,3002016-06-10 HIGH 8.8 CVE-2016-0910 EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file,… Data Domain Os after 5.7.1.0 Fix from $1,9502016-06-10 MEDIUM 6.7 CVE-2016-0908 EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leveraging administrative privileges. Isilon Onefs Mitigation only Fix from $1,6002016-06-04 MEDIUM 5.9 CVE-2016-0907 EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing … Isilon Onefs Mitigation only Fix from $1,6002016-05-30 MEDIUM 5.3 CVE-2016-0902 CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduc… Rsa Authentication Manager after 8.1 Fix from $1,6002016-05-07 MEDIUM 6.1 CVE-2016-0901 Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script … Rsa Authentication Manager after 8.1 Fix from $1,6002016-05-07 MEDIUM 6.1 CVE-2016-0900 Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script … Rsa Authentication Manager after 8.1 Fix from $1,6002016-05-07 MEDIUM 6.3 CVE-2016-0894 EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified paramet… Rsa Data Loss Prevention No fix yet Fix from $1,6002016-05-03 MEDIUM 6.1 CVE-2016-0892 Cross-site scripting (XSS) vulnerability in EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to inject arbitrary web script or … Rsa Data Loss Prevention No fix yet Fix from $1,6002016-05-03 HIGH 8.8 CVE-2016-0891 Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the au… Vipr Srm after 3.6.4 Fix from $1,9502016-04-20 HIGH 8.8 CVE-2016-0888 EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to modify objects via unspecified… Documentum D2 after 4.5 Fix from $1,9502016-04-07 MEDIUM 5.4 CVE-2016-0882 EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containin… Documentum Xcp Mitigation only Fix from $1,6002016-02-12 MEDIUM 6.5 CVE-2016-0881 EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection… Documentum Xcp Mitigation only Fix from $1,6002016-02-12 HIGH 8.4 CVE-2015-6850 EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privile… Vplex Geosynchrony No fix yet Fix from $1,9502015-12-28 HIGH 8.0 CVE-2015-4545 EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock … Isilon Onefs after 7.1.1.7 Fix from $1,9502015-12-21 HIGH 7.8 CVE-2015-6849 EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of servi… Networker Mitigation only Fix from $1,9502015-12-05 HIGH 8.5 CVE-2015-6848 EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not uni… Isilon Onefs after 7.1.1.0 Fix from $1,9502015-11-27 MEDIUM 6.8 CVE-2015-6846 EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a pro… Sourceone Email Supervisor after 7.1 Fix from $1,6002015-10-18 HIGH 7.5 CVE-2015-6845 EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtai… Sourceone Email Supervisor after 7.1 Fix from $1,9502015-10-18 MEDIUM 5.0 CVE-2015-6843 Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to… Sourceone Email Supervisor after 7.1 Fix from $1,6002015-10-18