Product:

Brightstor_arcserve_backup

(Ca)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 19
Date Id Summary Products Score Patch Annotated
2007-07-26 CVE-2007-3875 arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file. Anti\-Spyware, Anti\-Virus_for_the_enterprise, Anti_virus_sdk, Antispyware_for_the_enterprise, Antivirus_sdk, Brightstor_arcserve_backup, Brightstor_arcserve_client, Brightstor_enterprise_backup, Brigthstor_arcserve_client_for_windows, Common_services, Etrust_antivirus, Etrust_antivirus_gateway, Etrust_ez_antivirus, Etrust_ez_armor, Etrust_internet_security_suite, Etrust_intrusion_detection, Internet_security_suite, Secure_content_manager, Threat_manager, Unicenter_network_and_systems_management, Brightstor_arcserve_backup, Etrust_intrusion_detection, Protection_suites N/A
2005-12-31 CVE-2005-3653 Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. Brightstor_arcserve_backup, Brightstor_arcserve_backup_laptops_desktops, Brightstor_portal, Brightstor_process_automation_manager, Brightstor_san_manager, Brightstor_storage_resource_manager, Etrust_admin, Etrust_audit_aries, Etrust_audit_irecorder, Etrust_identity_minder, Etrust_integrated_threat_management, Itechnology_igateway, Unicenter_asset_portfolio_management, Unicenter_autosys_jm, Unicenter_service_delivery, Unicenter_service_desk, Unicenter_service_desk_knowledge_tools, Unicenter_service_fulfillment, Unicenter_service_metric_analysis, Brightstor_arcserve_backup, Brightstor_enterprise_backup, Etrust_audit_aries, Etrust_directory, Etrust_secure_content_manager, Unicenter_application_performance_monitor, Unicenter_application_server_managment, Unicenter_ca_web_services_distributed_management, Unicenter_exchange_management_console, Unicenter_management, Unicenter_service_catalog_fulfillment_accounting, Unicenter_service_fulfillment, Unicenter_service_level_management, Unicenter_web_server_management, Unicenter_web_services_distributed_management N/A
2007-04-25 CVE-2007-2139 Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. Brightstor_arcserve_backup, Business_protection_suite, Server_protection_suite, Brightstor_arcserve_backup, Business_protection_suite N/A
2008-05-21 CVE-2008-2241 Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writing to a startup file or configuration file. Brightstor_arcserve_backup, Server_protection_suite, Brightstor_arcserve_backup, Business_protection_suite N/A
2007-10-13 CVE-2007-5331 Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers. Brightstor_arcserve_backup, Brightstor_enterprise_backup, Business_protection_suite, Server_protection_suite, Brightstor_arcserve_backup, Business_protection_suite N/A
2007-10-13 CVE-2007-5329 Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption. Brightstor_arcserve_backup, Brightstor_enterprise_backup, Business_protection_suite, Server_protection_suite, Brightstor_arcserve_backup, Business_protection_suite N/A
2007-10-13 CVE-2007-5326 Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. Brightstor_arcserve_backup, Brightstor_enterprise_backup, Business_protection_suite, Server_protection_suite, Brightstor_arcserve_backup, Business_protection_suite N/A
2006-10-10 CVE-2006-5143 Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with... Brightstor_arcserve_backup, Brightstor_enterprise_backup, Business_protection_suite, Server_protection_suite, Brightstor_arcserve_backup N/A
2005-05-24 CVE-2005-1693 Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow. Etrust_antivirus, Etrust_antivirus_ee, Etrust_ez_armor, Etrust_ez_armor_le, Etrust_intrusion_detection, Etrust_secure_content_manager, Inoculateit, Brightstor_arcserve_backup, Etrust_antivirus, Etrust_intrusion_detection, Etrust_secure_content_manager, Vet_antivirus, Zonealarm, Zonealarm_antivirus N/A
2007-06-06 CVE-2007-2863 Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file. Anti\-Virus_for_the_enterprise, Brightstor_arcserve_backup, Brightstor_enterprise_backup, Common_services, Anti\-Virus_for_the_enterprise, Brightstor_arcserve_backup N/A