| OSVDB ID | Disclosure Date | Title |
|
40109
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly Computer Associates) eTrust Threat Management Console allow remote attackers to inject arbitrary web script or HTML via the IP Address field and other unspecified fields.
|
2007-12-05
|
CA eTrust Threat Management Console IP Address Field XSS
|
|
80485
Description:
CA eTrust Vet Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. This may allow a context-dependent attacker to use a specially crafted CAB file in order to bypass the scanning functionality, allowing for the delivery of malware.
|
2012-03-19
|
CA eTrust Vet Antivirus Malformed CAB File Handling Scan Bypass
|
|
80425
Description:
CA eTrust Vet Antivirus contains a flaw related to the anti-virus / anti-malware scanning functionality. This may allow a context-dependent attacker to use a specially crafted ELF file in order to bypass the scanning functionality, allowing for the delivery of malware.
|
2012-03-19
|
CA eTrust Vet Antivirus Malformed ELF File Handling Scan Bypass
|
|
74119
Description:
(Description Provided by CVE) : Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.
|
2011-07-21
|
CA Gateway Security for HTTP Icihttp.exe URL Parsing Memory Corruption
|
|
57168
Description:
(Description Provided by CVE) : kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet.
|
2009-08-18
|
CA Host-Based Intrusion Prevention System kmxIds.sys Crafted Packet Handling DoS
|
|
37998
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer.
|
2007-10-18
|
CA Host-Based Intrusion Prevention System Server Log Data XSS
|
|
88557
Description:
CA IdentityMinder contains an unspecified flaw that may allow a remote attacker to execute arbitrary commands or manipulate arbitrary data. No further details have been provided.
|
2012-12-20
|
CA IdentityMinder Unspecified Arbitrary Command Execution
|
|
88559
Description:
CA IdentityMinder contains an unspecified flaw that may allow an attacker to gain access to unauthorized privileges. No further details have been provided.
|
2012-12-20
|
CA IdentityMinder Unspecified Privilege Escalation
|
|
19920
Description:
A remote overflow exists in Computer Associates iGateway. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted HTTP GET request, a remote attacker can cause arbitrary code execution with SYSTEM privileges resulting in a loss of integrity.
|
2005-10-10
|
CA iGateway Debug Mode HTTP GET Request Overflow
|
|
22688
Description:
A remote overflow exists in iGateway. The web server fails to properly validate the Content-Length header, resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code to be executed, resulting in a loss of integrity and/or availability.
|
2006-01-23
|
CA iGateway Service Content-Length Overflow
|
|
69518
Description:
CA Internet Security Suite Plus contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a pool corruption vulnerability in the handling of IOTCL 0x88000080 in the KmxSbx.sys kernel driver is exploited to cause a buffer overflow, allowing a local attacker to execute arbitrary code with elevated privileges.
|
2010-11-28
|
CA Internet Security Suite Plus KmxSbx.sys IOCTL Handling Local Overflow
|
|
45679
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.
|
2008-05-28
|
CA Internet Security Suite UmxEventCli.CachedAuditDataList.1 ActiveX (UmxEventCli.dll) SaveToFile Method Arbitrary File Overwrite
|
|
57228
Description:
(Description Provided by CVE) : vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.
|
2009-08-18
|
CA Internet Security Suite vetmonnt.sys Crafted IOCTL Call Local DoS
|
|
14323
Description:
CA License Manager contains a flaw that allows a remote attacker to create arbitrary files on the file system. The issue is due to the License Client not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the PUTOLF command.
|
2005-03-02
|
CA License Client PUTOLF Traversal Arbitrary File Creation
|
|
14320
Description:
A remote overflow exists in License Manager. The program fails to validate GCR Checksum packets resulting in a stack overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-03-02
|
CA License Server/Client GCR Checksum Multiple Overflow
|
|
14321
Description:
A remote overflow exists in License Manager. The program fails to validate GCR Request packets resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-03-02
|
CA License Server/Client GCR Request Packet Multiple Overflows
|
|
14389
Description:
Muliple remote overflows exist in CA License Manager. The LIC98RMT.EXE component fails to validate the parameters passed to several commands resulting in buffer overflows. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-03-02
|
CA License Server/Client Multiple Command Remote Overflow
|
|
21146
Description:
CA Message Queueing contains a flaw that may allow a remote denial of service. The issue is triggered when crafted messages are received on TCP port 4105, and will result in loss of availability for the service.
|
2006-02-02
|
CA Message Queuing (CAM / CAFT) Port 4105 Crafted Message DoS
|
|
21147
Description:
(Description Provided by CVE) : Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages.
|
2006-02-02
|
CA Message Queuing Spoofed CAM Control Message DoS
|
|
16027
Description:
(Description Provided by CVE) : Buffer overflows in Computer Associates MLink (CA-MLink) 6.5 and earlier may allow local users to execute arbitrary code via long command line arguments to (1) mlclear or (2) mllock.
|
2002-04-05
|
CA MLink mlclear Command Line Argument Overflow
|
|
16028
Description:
(Description Provided by CVE) : Buffer overflows in Computer Associates MLink (CA-MLink) 6.5 and earlier may allow local users to execute arbitrary code via long command line arguments to (1) mlclear or (2) mllock.
|
2002-04-05
|
CA MLink mllock Command Line Argument Overflow
|
|
85880
Description:
Multiple CA products contain a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when the CA Licensing component fails to securely handle system commands. This may allow a local attacker to gain escalated privileges and execute arbitrary commands.
|
2012-10-01
|
CA Multiple Product CA Licensing Component System Command Handling Local Privilege Escalation
|
|
85879
Description:
Multiple CA products contain a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in the CA Licensing component during the handling of user permissions. This may allow a local attacker to edit or change an arbitrary file in order to gain escalated privileges.
|
2012-10-01
|
CA Multiple Product CA Licensing Component User Permission Handling Arbitrary File Manipulation Local Privilege Escalation
|
|
45367
Description:
(Description Provided by CVE) : Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writing to a startup file or configuration file.
|
2008-05-19
|
CA Multiple Product caloggerd Log Daemon Traversal Arbitrary File Manipulation
|
|
45368
Description:
(Description Provided by CVE) : Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function.
|
2008-05-19
|
CA Multiple Product xdr_rwsstring() Library Function Remote Overflow
|
|
44040
Description:
Multiple buffer overflows exist in multiple CA products. The Alert Notification Server fails to validate data passed to multiple unspecified parameters, in addition to known RPC requests, resulting in a stack overflow. With a specially crafted request, a remote authenticated attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-04-03
|
CA Multiple Products Alert Notification Server Multiple Unspecified Remote Overflows
|
|
16780
Description:
A remote overflow exists in multiple products which rely on Computer Associates Vet Antivirus engine. The engine fails to perform bounds checking while analyzing an OLE stream resulting in a heap overflow. With a specially crafted Microsoft Office document, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-05-23
|
CA Multiple Products Vet Engine OLE Stream Remote Overflow
|
|
58691
Description:
(Description Provided by CVE) : Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.
|
2009-10-08
|
CA Multiple Products Anti-Virus Engine arclib Component RAR File Handling Memory Corruption DoS
|
|
38611
Description:
(Description Provided by CVE) : arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
|
2007-07-24
|
CA Multiple Products arclib.dll Crafted CHM File Processing DoS
|
|
29534
Description:
(Description Provided by CVE) : Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.
|
2006-10-05
|
CA Multiple Products ASBRDCST.DLL (casdscsvc.exe) Hostname Remote Overflow
|