Filtered by vendor Emc
Subscribe
Total
414 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-1119 | 1 Emc | 1 Replistor | 2023-12-10 | 10.0 HIGH | N/A |
Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via a crafted message to (1) ctrlservice.exe or (2) rep_srv.exe, possibly related to an integer overflow. | |||||
CVE-2008-0962 | 1 Emc | 1 Diskxtender | 2023-12-10 | 9.0 HIGH | N/A |
Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface. | |||||
CVE-2008-3684 | 1 Emc | 1 Documentum Applicationxtender | 2023-12-10 | 10.0 HIGH | N/A |
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606. | |||||
CVE-2009-0311 | 1 Emc | 1 Autostart | 2023-12-10 | 10.0 HIGH | N/A |
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer. | |||||
CVE-2008-0963 | 1 Emc | 1 Diskxtender | 2023-12-10 | 9.0 HIGH | N/A |
Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface. | |||||
CVE-2008-3685 | 1 Emc | 1 Documentum Applicationxtender Workflow Manager | 2023-12-10 | 10.0 HIGH | N/A |
Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606. | |||||
CVE-2008-3370 | 1 Emc | 1 Centera Universal Access | 2023-12-10 | 7.5 HIGH | N/A |
SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field. | |||||
CVE-2009-3744 | 1 Emc | 1 Replistor | 2023-12-10 | 5.0 MEDIUM | N/A |
rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144. | |||||
CVE-2007-3618 | 1 Emc | 1 Legato Networker | 2023-12-10 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd." | |||||
CVE-2007-5323 | 1 Emc | 1 Replistor | 2023-12-10 | 10.0 HIGH | N/A |
The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor to create a smaller buffer than expected, which triggers a buffer overflow when that buffer is used in a recv function call. | |||||
CVE-2006-7199 | 1 Emc | 1 Rsa Security Sitekey | 2023-12-10 | 8.5 HIGH | N/A |
EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server. NOTE: the vendor disputes the severity of the issue, stating that it is easier to monitor this attack than "attacks against static web pages." | |||||
CVE-2007-6426 | 1 Emc | 1 Replistor | 2023-12-10 | 7.8 HIGH | N/A |
Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via crafted compressed data. | |||||
CVE-2007-5024 | 1 Emc | 1 Vmware Server | 2023-12-10 | 2.1 LOW | N/A |
EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2005-3620. | |||||
CVE-2006-7201 | 1 Emc | 1 Rsa Security Sitekey | 2023-12-10 | 9.3 HIGH | N/A |
EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared object), which might allow remote attackers to obtain the token via HTTP. | |||||
CVE-2006-7200 | 1 Emc | 1 Rsa Security Sitekey | 2023-12-10 | 9.0 HIGH | N/A |
EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier for attackers to bypass one stage of authentication by stealing and replaying a token. | |||||
CVE-2008-0656 | 1 Emc | 2 Documentum Administrator, Documentum Webtop | 2023-12-10 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute. | |||||
CVE-2007-4155 | 1 Emc | 1 Vmware | 2023-12-10 | 9.3 HIGH | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first two arguments to the (1) CreateProcess or (2) CreateProcessEx method. | |||||
CVE-2007-4058 | 1 Emc | 1 Vmware | 2023-12-10 | 4.3 MEDIUM | N/A |
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method. | |||||
CVE-2006-3892 | 1 Emc | 1 Networker | 2023-12-10 | 10.0 HIGH | N/A |
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands. | |||||
CVE-2006-2154 | 1 Emc | 1 Retrospect | 2023-12-10 | 7.2 HIGH | N/A |
EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the File>Open dialog. |