Show filters
46 Total Results
Displaying 31-40 of 46
Sort by:
Attacker Value
Unknown
CVE-2016-0920
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
0
Attacker Value
Unknown
CVE-2016-0905
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command.
0
Attacker Value
Unknown
CVE-2016-0903
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
0
Attacker Value
Unknown
CVE-2016-0906
Disclosure Date: July 06, 2016 (last updated November 25, 2024)
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.
0
Attacker Value
Unknown
CVE-2015-4527
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters.
0
Attacker Value
Unknown
CVE-2014-4623
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
0
Attacker Value
Unknown
CVE-2013-3274
Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-3275
Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities."
0
Attacker Value
Unknown
CVE-2013-0945
Disclosure Date: May 03, 2013 (last updated October 05, 2023)
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2013-0944
Disclosure Date: May 03, 2013 (last updated October 05, 2023)
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.
0