Skip to main content

Vendor archive

emc CVEs

Beta · best-effort

414 CVEs tagged to vendor emc78 Critical, 109 High, 197 Medium, 30 Low, 0 Unrated.

CVE-2015-0548

Published Jul 4, 2015

The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Que…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0547

Published Jul 4, 2015

The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Quer…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0545

Published Jun 29, 2015

EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0550

Published Jun 28, 2015

Directory traversal vulnerability in EMC Documentum Thumbnail Server 6.7SP1 before P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P01 allows remote attacke…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0549

Published Jun 28, 2015

Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-0526

Published Jun 22, 2015

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Validation Manager (RVM) 3.2 before build 201 allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0540

Published May 25, 2015

SQL injection vulnerability in the xAdmin interface in EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 allows remote authenticated users to execute arbitrary…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0538

Published May 7, 2015

ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0531

Published May 7, 2015

EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0532

Published May 1, 2015

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0530

Published Apr 17, 2015

Buffer overflow in an unspecified function in nsr_render_log in EMC NetWorker before 8.0.4.3, 8.1.x before 8.1.2.6, and 8.2.x before 8.2.1.2 allows local users to gain privileges…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0529

Published Apr 5, 2015

EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain po…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0528

Published Mar 29, 2015

The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local users to gain privileges by l…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0525

Published Mar 12, 2015

The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0524

Published Mar 12, 2015

SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0519

Published Feb 14, 2015

The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-0518

Published Feb 14, 2015

The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0517

Published Feb 14, 2015

The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allow…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0512

Published Feb 2, 2015

Open redirect vulnerability in EMC Unisphere Central before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified pa…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0516

Published Jan 21, 2015

Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 176-200 of 414 CVEsPage 8 of 17