VYPR

Vendor CVEs

EMC Corporation

All CVEs

570 total · sorted by risk
  • CVE-2012-0401Mar 20, 2012
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2012-0400Mar 20, 2012
    risk 0.00cvss epss 0.01

    EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

  • CVE-2012-0399Mar 20, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-0404Mar 15, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-0398Mar 15, 2012
    risk 0.00cvss epss 0.01

    EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors.

  • CVE-2012-0397Mar 6, 2012
    risk 0.00cvss epss 0.03

    Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

  • CVE-2012-0396Feb 6, 2012
    risk 0.00cvss epss 0.01

    EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.

  • CVE-2011-4144Feb 2, 2012
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user privileges" by leveraging system administrator privileges.

  • CVE-2012-0395Jan 27, 2012
    risk 0.00cvss epss 0.03

    Buffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

  • CVE-2011-4143Jan 27, 2012
    risk 0.00cvss epss 0.01

    EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors.

  • CVE-2011-4142Jan 19, 2012
    risk 0.00cvss epss 0.00

    The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files.

  • CVE-2011-4141Dec 17, 2011
    risk 0.00cvss epss 0.02

    Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file.

  • CVE-2011-2742Dec 14, 2011
    risk 0.00cvss epss 0.01

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic evaluation upon receipt of device tokens from mobile apps, which might allow remote attackers to bypass intended application…

  • CVE-2011-2741Dec 14, 2011
    risk 0.00cvss epss 0.01

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Recovery and Device Identification, which might allow remote attackers to bypass intended security restrictions on a (1) previously…

  • CVE-2011-2740Nov 9, 2011
    risk 0.00cvss epss 0.03

    EMC RSA Key Manager (RKM) Appliance 2.7 SP1 before 2.7.1.6, when Firefox 4.x or 5.0 is used, does not properly terminate a user session upon a logout action, which makes it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.

  • CVE-2011-2739Nov 9, 2011
    risk 0.00cvss epss 0.03

    The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file.

  • CVE-2011-1740Sep 19, 2011
    risk 0.00cvss epss 0.01

    EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.

  • CVE-2011-2735Aug 23, 2011
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted message over TCP.

  • CVE-2011-2733Aug 18, 2011
    risk 0.00cvss epss 0.01

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authentication information during a session, which allows remote authenticated users to bypass intended access restrictions via vectors related…

  • CVE-2011-1744Aug 1, 2011
    risk 0.00cvss epss 0.01

    EMC Captiva eInput 2.1.1 before 2.1.1.37 does not restrict the origin of calls to ActiveX functions, which allows remote attackers to read arbitrary files or cause a denial of service via a crafted web site.

  • CVE-2011-1743Aug 1, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in EMC Captiva eInput 2.1.1 before 2.1.1.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-1742Aug 1, 2011
    risk 0.00cvss epss 0.00

    EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.

  • CVE-2011-1424May 24, 2011
    risk 0.00cvss epss 0.01

    The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive…

  • CVE-2011-1423May 5, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in RSA Data Loss Prevention (DLP) Enterprise Manager 8.x before 8.5 SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-1422Apr 22, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2011-1421Apr 22, 2011
    risk 0.00cvss epss 0.00

    EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors.

  • CVE-2011-1420Mar 28, 2011
    risk 0.00cvss epss 0.00

    EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

  • CVE-2011-0648Mar 16, 2011
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.

  • CVE-2011-0442Mar 16, 2011
    risk 0.00cvss epss 0.01

    The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to obtain sensitive information by sniffing the network.

  • CVE-2011-0322Mar 16, 2011
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in EMC RSA Access Manager Server 5.5.x, 6.0.x, and 6.1.x allows remote attackers to access resources via unknown vectors.

  • CVE-2011-0321Feb 1, 2011
    risk 0.00cvss epss 0.03

    librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and…

  • CVE-2010-2633Aug 2, 2010
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in EMC Disk Library (EDL) before 3.2.7, 3.3.x before 3.3.2 epatch 8, and 4.0.x before 4.0.1 epatch 4 allows remote attackers to cause a denial of service (communication-module crash) by sending a crafted message through TCP.

  • CVE-2010-1904Jun 7, 2010
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in EMC RSA Key Manager (RKM) C Client 1.5.x allows user-assisted remote attackers to execute arbitrary SQL commands via the metadata section of encrypted key data.

  • CVE-2010-1919May 28, 2010
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP.

  • CVE-2008-3684Oct 22, 2009
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606.

  • CVE-2009-1119Apr 15, 2009
    risk 0.00cvss epss 0.05

    Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via a crafted message to (1) ctrlservice.exe or (2) rep_srv.exe, possibly related to an integer overflow.

  • CVE-2008-4916Apr 6, 2009
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, and 2.5.1 and…

  • CVE-2008-6219Feb 20, 2009
    risk 0.00cvss epss 0.03

    nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0…

  • CVE-2009-0311Jan 27, 2009
    risk 0.00cvss epss 0.05

    The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.

  • CVE-2008-5420Dec 10, 2008
    risk 0.00cvss epss 0.02

    The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which allows remote attackers to read arbitrary files.

  • CVE-2008-3288Jul 24, 2008
    risk 0.00cvss epss 0.02

    The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-dependent attackers to recover passwords.

  • CVE-2008-3290Jul 24, 2008
    risk 0.00cvss epss 0.03

    retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daemon crash) via a series of long packets containing 0x00 characters to TCP port 497 that trigger memory corruption, probably involving an English product version…

  • CVE-2008-3287Jul 24, 2008
    risk 0.00cvss epss 0.03

    retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daemon crash) via malformed packets to TCP port 497, which trigger a NULL pointer dereference.

  • CVE-2008-0963Apr 14, 2008
    risk 0.00cvss epss 0.03

    Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface.

  • CVE-2008-0962Apr 14, 2008
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface.

  • CVE-2007-6426Feb 21, 2008
    risk 0.00cvss epss 0.03

    Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via crafted compressed data.

  • CVE-2008-0656Feb 7, 2008
    risk 0.00cvss epss 0.03

    Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.

  • CVE-2007-5323Oct 11, 2007
    risk 0.00cvss epss 0.05

    The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor to create a smaller buffer than expected, which triggers a buffer overflow when that buffer is used in a recv function call.

  • CVE-2007-4497Sep 21, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build…

  • CVE-2007-4496Sep 21, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build…

Page 11 of 12