VYPR

Enterprise Vault

by Symantec

CVEs (19)

  • CVE-2024-53915CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53914CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53913CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53912CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53911CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53910CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2024-53909CriNov 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

  • CVE-2021-44682CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44681CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44680CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44679CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44678CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2021-44677CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited…

  • CVE-2020-36164CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in Veritas Enterprise Vault through 14.0. On start-up, it loads the OpenSSL library. The OpenSSL library then attempts to load the openssl.cnf configuration file (which does not exist) at the following locations in both the System drive (typically C:\)…

  • CVE-2013-1609HigMar 26, 2013
    risk 0.51cvss 7.8epss 0.00

    Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.

  • CVE-2024-52944MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an…

  • CVE-2024-52943MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…

  • CVE-2024-52942MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…

  • CVE-2024-52941MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an…