Skip to main content

Vendor archive

emc CVEs

Beta · best-effort

414 CVEs tagged to vendor emc78 Critical, 109 High, 197 Medium, 30 Low, 0 Unrated.

CVE-2013-3286

Published Nov 6, 2013

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3285

Published Nov 2, 2013

The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cl…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3280

Published Oct 25, 2013

EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to bypass intended access restricti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3279

Published Oct 16, 2013

EMC Atmos before 2.1.4 has a blank password for the PostgreSQL account, which allows remote attackers to obtain sensitive administrative information via a database-server connecti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3277

Published Sep 5, 2013

Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vect…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3276

Published Sep 5, 2013

EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deactivated account.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3271

Published Aug 28, 2013

EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, instead of within the Agent code…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0943

Published Jul 31, 2013

EMC NetWorker 7.6.x and 8.x before 8.1 allows local users to obtain sensitive configuration information by leveraging operating-system privileges to perform decryption with nsradm…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3272

Published Jul 8, 2013

EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for local users to obtain sensitive information by reading a fil…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0946

Published May 10, 2013

Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code via crafted commands.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0945

Published May 3, 2013

EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0944

Published May 3, 2013

The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 276-300 of 414 CVEsPage 12 of 17