Show filters
46 Total Results
Displaying 31-40 of 46
Sort by:
Attacker Value
Unknown

CVE-2016-0920

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
0
Attacker Value
Unknown

CVE-2016-0905

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command.
0
Attacker Value
Unknown

CVE-2016-0903

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
0
Attacker Value
Unknown

CVE-2016-0906

Disclosure Date: July 06, 2016 (last updated November 25, 2024)
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
0
Attacker Value
Unknown

CVE-2015-4527

Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters.
0
Attacker Value
Unknown

CVE-2014-4623

Disclosure Date: October 25, 2014 (last updated October 05, 2023)
EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
0
Attacker Value
Unknown

CVE-2013-3274

Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3275

Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities."
0
Attacker Value
Unknown

CVE-2013-0945

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2013-0944

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.
0