| OSVDB ID | Disclosure Date | Title |
|
54302
Description:
C2C Forward Auction Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
C2C Forward Auction Creator admin.asp Multiple Parameter SQL Injection
|
|
54305
Description:
C2C Reverse Auction Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
C2C Reverse Auction Creator admin.asp Multiple Parameter SQL Injection
|
|
42100
Description:
Unknown / Incomplete
|
2005-08-05
|
c3p0 Log User Credential Cleartext Disclosure
|
|
54570
Description:
Unknown / Incomplete
|
2009-05-14
|
c7 Portal c7portal Cookie Manipulation Admin Authentication Bypass
|
|
53604
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.
|
2009-01-27
|
CA Anti-Virus Arclib Library (arclib.dll) Malformed Archive Scan Bypass
|
|
35244
Description:
A buffer overflow exists in multiple CA products. The Anti-Virus engine fails to validate CAB archive files resulting in a stack overflow. With a specially crafted CAB containing a file with a long filename, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-06-05
|
CA Anti-Virus Engine CAB Archive Filename Parsing Overflow
|
|
35245
Description:
A buffer overflow exists in multiple CA products. The Anti-Virus engine fails to validate CAB files resulting in a stack overflow. With a specially crafted CAB file containing a malformed "coffFiles" field, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-06-05
|
CA Anti-Virus Engine CAB Header Parsing Overflow
|
|
30845
Description:
(Description Provided by CVE) : The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.
|
2006-12-13
|
CA Anti-Virus Multiple Driver Local DoS
|
|
72125
Description:
CA Arcot WebFort Versatile Authentication contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate certain unspecified input. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|
2011-04-26
|
CA Arcot WebFort Versatile Authentication Server Unspecified Arbitrary Site Redirect
|
|
72124
Description:
CA Arcot WebFort Versatile Authentication Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-04-26
|
CA Arcot WebFort Versatile Authentication Server Unspecified XSS
|
|
5482
Description:
(Description Provided by CVE) : Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
|
2004-04-08
|
CA ARCserve Backup Agent Credential Disclosure
|
|
49471
Description:
(Description Provided by CVE) : Unspecified vulnerability in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash of multiple services) via crafted authentication credentials, related to "insufficient validation."
|
2008-10-09
|
CA ARCserve Backup asdbapi.dll Crafted Authentication Credential Remote DoS
|
|
49470
Description:
(Description Provided by CVE) : Unspecified vulnerability in the database engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request, related to "insufficient validation."
|
2008-10-09
|
CA ARCserve Backup Database Engine Service (asdbapi.dll) Unspecified Crafted Request Remote DoS
|
|
63260
Description:
Unknown / Incomplete
|
2010-03-18
|
CA ARCserve Backup for Windows JRE Multiple Unspecified Issues
|
|
55227
Description:
(Description Provided by CVE) : The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.
|
2009-06-15
|
CA ARCserve Backup for Windows Message Engine 0x3B Message Invalid Stub Data RPC Marshalling Error Remote DoS
|
|
55226
Description:
(Description Provided by CVE) : The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.
|
2009-06-15
|
CA ARCserve Backup for Windows Message Engine ASCORE Module 0x13 Message Handling Remote DoS
|
|
50683
Description:
(Description Provided by CVE) : The LDBserver service in the server in CA ARCserve Backup 11.1 through 12.0 on Windows allows remote attackers to execute arbitrary code via a handle_t argument to an RPC endpoint in which the argument refers to an incompatible procedure.
|
2008-12-10
|
CA ARCserve Backup on Windows LDBserver Service Client Data Verification Weakness
|
|
65242
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA ARCserve Backup r11.5 SP4, r12.0 SP2, and r12.5 SP1 on Windows allows local users to obtain sensitive information via unknown vectors.
|
2010-06-03
|
CA ARCserve Backup on Windows Unspecified Local Information Disclosure
|
|
49468
Description:
ARCServe Backup is prone to an overflow condition. The RPC interface fails to properly sanitize user-supplied input to opcode 0x342 resulting in a buffer overflow. With a specially crafted request, a remote attacker can potentially cause arbitrary code execution.
|
2008-10-09
|
CA ARCserve Backup RPC Interface (asdbapi.dll) Traversal Arbitrary Command Execution
|
|
49469
Description:
(Description Provided by CVE) : Unspecified vulnerability in the tape engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash) via a crafted request.
|
2008-10-09
|
CA ARCserve Backup Tape Engine Service (asdbapi.dll) Unspecified Crafted Request Remote DoS
|
|
70233
Description:
By default, CA ARCserve D2D deploys Axis2 with default credentials. The admin account has a password of axis2 which is publicly known and documented. This allows attackers to trivially access the program or system and gain privileged access. An attacker may also then upload a crafted .aar file to execute arbitrary code.
|
2010-12-30
|
CA ARCserve D2D Axis2 Default Credentials
|
|
74162
Description:
(Description Provided by CVE) : BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.
|
2011-07-25
|
CA ARCserve D2D homepageServlet Google Web Toolkit (GWT) RPC Request Parsing Admin Credential Disclosure
|
|
5483
Description:
Computer Associates ARCserver contains a flaw that may lead to an unauthorized information disclosure or possibly system compromise. The issue is triggered by an attacker connecting to the ARCSERVE$ share.
|
2001-09-14
|
CA ARCserve Hidden Share Information Disclosure
|
|
10083
Description:
(Description Provided by CVE) : ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
|
1999-02-21
|
CA ARCserve NT Agents Weak Password Encryption
|
|
6765
Description:
(Description Provided by CVE) : Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.
|
2001-05-18
|
CA ARCserveIT asagent inetd.tmp Temporary File Symlink Arbitrary File Overwrite
|
|
10085
Description:
(Description Provided by CVE) : uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.
|
2000-07-28
|
CA ARCServeIT uagentsetup agent.cfg Race Condition Privilege Escalation
|
|
18501
Description:
A remote stack-based buffer overflow exists in Brightstor Arcserve. The agent software fails to validate user-supplied input resulting in a long string overflow. With a specially crafted request of 3168 bytes to port 6070, an attacker can execute arbitrary code with System privilege resulting in a loss of confidentiality and integrity.
|
2005-08-02
|
CA BrightStor ARCserve Backup Agent for Windows Long String Overflow
|
|
31318
Description:
A buffer overflow exists in ARCserve Backup. The message engine fails to validate RPC requests on TCP ports 6503 and 6504 resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-10-07
|
CA BrightStor ARCserve Backup ASCORE.dll (msgeng.exe) Multiple RPC Remote Overflow
|
|
57056
Description:
A remote overflow exists in a DLL distributed with CA BrightStor ARCServe BackUp. The application fails to properly bound check RPC messages resulting in an overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of confidentiality, integrity, and/or availability.
|
2007-10-11
|
CA BrightStor ARCServe BackUp AScore.dll Remote Overflow
|
|
41374
Description:
(Description Provided by CVE) : The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.
|
2007-10-11
|
CA BrightStor ARCServe Backup cadbd RPC Service Handle Argument Remote Memory Corruption
|