Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2013-3274

Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3275

Disclosure Date: July 19, 2013 (last updated October 05, 2023)
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities."
0
Attacker Value
Unknown

CVE-2013-0945

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-2291

Disclosure Date: January 21, 2013 (last updated October 05, 2023)
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
0
Attacker Value
Unknown

CVE-2011-1740

Disclosure Date: September 19, 2011 (last updated October 04, 2023)
EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.
0
Attacker Value
Unknown

CVE-2011-0648

Disclosure Date: March 16, 2011 (last updated October 04, 2023)
Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-1919

Disclosure Date: May 28, 2010 (last updated October 04, 2023)
Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP.
0