Skip to main content

Vendor archive

broadcom CVEs

Beta · best-effort

644 CVEs tagged to vendor broadcom131 Critical, 250 High, 242 Medium, 21 Low, 0 Unrated.

CVE-2020-15382

Published Jun 9, 2021

Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15381

Published Jun 9, 2021

Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26314

Published Jun 9, 2021

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating poin…

CVSS 5.5 · Medium

CVE-2021-26313

Published Jun 9, 2021

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions,…

CVSS 5.5 · Medium

CVE-2021-21981

Published Apr 19, 2021

VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22890

Published Apr 1, 2021

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HT…

CVSS 3.7 · Low

CVE-2021-22876

Published Apr 1, 2021

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libc…

CVSS 5.3 · Medium

CVE-2021-28248

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /we…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28246

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-25013

Published Jan 4, 2021

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

CVSS 5.9 · Medium

CVE-2020-35507

Published Jan 4, 2021

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processe…

CVSS 5.5 · Medium

CVE-2020-35496

Published Jan 4, 2021

There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NU…

CVSS 5.5 · Medium

CVE-2020-35495

Published Jan 4, 2021

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The gr…

CVSS 5.5 · Medium

CVE-2020-35494

Published Jan 4, 2021

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The…

CVSS 6.1 · Medium

CVE-2020-35493

Published Jan 4, 2021

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that…

CVSS 5.5 · Medium

CVE-2020-15376

Published Dec 11, 2020

Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15375

Published Dec 11, 2020

Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccryp…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 644 CVEsPage 12 of 26