Search: "emc"

719 CVEs found

CVE-2002-0113
4.6 MEDIUM

EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly g...

Published: 2002-03-25
Products: 1
Vendors:
emc
CVE-2002-0114
4.6 MEDIUM

EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: thi...

Published: 2002-03-25
Products: 1
Vendors:
emc
CVE-2005-2357
5.0 MEDIUM

Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Published: 2005-08-16
Products: 4
Vendors:
emc
CVE-2005-2358
5.0 MEDIUM

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

Published: 2005-08-16
Products: 4
Vendors:
emc

EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote att...

Published: 2005-08-23
Products: 10
Vendors:
sun emc

EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modi...

Published: 2005-08-23
Products: 10
Vendors:
sun emc
CVE-2005-0359
6.4 MEDIUM

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which a...

Published: 2005-08-23
Products: 10
Vendors:
sun emc

Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterpri...

Published: 2005-12-31
Products: 6
Vendors:
emc
CVE-2005-3659
5.0 MEDIUM

nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1...

Published: 2005-12-31
Products: 3
Vendors:
emc
CVE-2006-0995
5.0 MEDIUM

EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup serv...

Published: 2006-03-03
Products: 2
Vendors:
emc_dantz

EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the Fi...

Published: 2006-05-03
Products: 3
Vendors:
emc
CVE-2006-2155
4.6 MEDIUM

EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper ...

Published: 2006-05-03
Products: 3
Vendors:
emc

Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet to port 497.

Published: 2006-05-16
Products: 4
Vendors:
emc
CVE-2006-3547
5.5 MEDIUM

EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machin...

Published: 2006-07-13
Products: 1
Vendors:
vmware
CVE-2007-0222
5.0 MEDIUM

Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequenc...

Published: 2007-01-17
Products: 1
Vendors:
oracle
CVE-2007-1070
10.0 HIGH

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted...

Published: 2007-02-21
Products: 10
Vendors:
trend_micro microsoft
CVE-2006-3892
10.0 HIGH

The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands.

Published: 2007-03-02
Products: 1
Vendors:
emc
CVE-2007-2267
6.8 MEDIUM

Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corr...

Published: 2007-04-25
Products: 5
Vendors:
sun

EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a leg...

Published: 2007-04-30
Products: 1
Vendors:
emc

EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier for attackers to bypass one stage of authentication b...

Published: 2007-04-30
Products: 1
Vendors:
emc