RSS   Vulnerabilities for 'Backup exec for windows server'   RSS

2008-12-10
 
CVE-2008-5408

CWE-119
 

 
Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2008-5407.

 
 
CVE-2008-5407

CWE-287
 

 
Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors.

 
2008-02-29
 
CVE-2007-6017

CWE-20
 

 
The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary files, via string values of the (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, and (19) _MonthText11 properties. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.

 
 
CVE-2007-6016

 

 
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.

 

 >>> Vendor: Symantec 241 Products
JAVA
Mail-gear
Raptor firewall
Norton antivirus
Pcanywhere
Norton utilities
I-gear
Liveupdate
Norton ghost
Enterprise firewall
Velociraptor
Gateway security
Norton internet security
Norton personal firewall
Backup exec
Firewall vpn appliance 100
Firewall vpn appliance 200
Firewall vpn appliance 200r
Sygate personal firewall
Security check
Norton system works
Windows liveupdate
VXFS
Proxysg
Clientless vpn gateway 4400
Gateway security 5400
Antivirus scan engine
Norton antispam
Gateway security 5300
Client firewall
Client security
Brightmail antispam
Nexland isb soho firewall appliance
Nexland pro100 firewall appliance
Nexland pro400 firewall appliance
Nexland pro800 firewall appliance
Nexland pro800turbo firewall appliance
Nexland wavebase firewall appliance
Gateway security 320
Gateway security 360
Gateway security 360r
On command ccm
On icommand
Security check virus detection
Powerquest deploycenter
Web security
Mail security
Sav filter domino nt ports
Sav filter for domino nt
Gateway security 460
Symav filter domino nt
Deployment solution
Reporter
Netbackup enterprise server
Netbackup server
Antivirus scan engine for network attached storage
Antivirus
Discovery
On command discovery
Gateway security 300
Gateway security 400
Gateway security 5000 series
Gateway security 5100
Gateway security 5310
Sygate management server
Ghost solutions suite
Security information manager
On-demand agent
On-demand protection
Enterprise security manager
Host ids
Scan engine
Veritas netbackup client
Veritas netbackup enterprise server
Veritas netbackup server
Naveng driver
Navex15 driver
Sygate network access control
Network access control
Automated support assistant
Livestate agent for windows
Symantec antivirus filtering +for domino
Mail security 8820 appliance
Veritas volume replicator
Norton 360
Veritas storage foundation
Backupexec system recovery
Livestate recovery
Norton save and recovery
Reporting server
Veritas backup exec
Altiris deployment solution
Mail security appliance
Backup exec for windows server
Symantec antivirus clearswift
Symantec antivirus filtering domino mpe
Symantec antivirus messaging
Symantec antivirus microsoft sharepoint
Symantec antivirus ms isa
Symantec antivirus network attached storage
See all Products for Vendor Symantec


Copyright 2024, cxsecurity.com

 

Back to Top