Skip to main content

Vendor archive

broadcom CVEs

Beta · best-effort

644 CVEs tagged to vendor broadcom131 Critical, 250 High, 242 Medium, 21 Low, 0 Unrated.

CVE-2020-12740

Published May 8, 2020

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11660

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11659

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11666

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11665

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11664

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11663

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11662

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive informati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11661

Published Apr 15, 2020

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8012

Published Feb 18, 2020

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8011

Published Feb 18, 2020

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (controller) component. A remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8010

Published Feb 18, 2020

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8648

Published Feb 6, 2020

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

CVSS 7.1 · High

CVE-2019-15126

Published Feb 5, 2020

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that…

CVSS 3.1 · Low
evidence mentions
7
Buzz score
28.8

CVE-2019-16204

Published Feb 5, 2020

Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an exter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16203

Published Feb 5, 2020

Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 644 CVEsPage 14 of 26