Vulnerabilities
Vulnerable Software
Emc:  Security Vulnerabilities
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
CVSS Score
10.0
EPSS Score
0.103
Published
2009-01-27
Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attackers to execute arbitrary code via multiple SST_CTGTRANS requests.
CVSS Score
10.0
EPSS Score
0.242
Published
2008-12-10
The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which allows remote attackers to read arbitrary files.
CVSS Score
7.8
EPSS Score
0.008
Published
2008-12-10
SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field.
CVSS Score
7.5
EPSS Score
0.007
Published
2008-07-30
The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-dependent attackers to recover passwords.
CVSS Score
5.0
EPSS Score
0.007
Published
2008-07-24
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.
CVSS Score
9.8
EPSS Score
0.023
Published
2008-04-14
Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface.
CVSS Score
9.0
EPSS Score
0.063
Published
2008-04-14
Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface.
CVSS Score
9.0
EPSS Score
0.038
Published
2008-04-14
Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via crafted compressed data.
CVSS Score
7.8
EPSS Score
0.029
Published
2008-02-21
Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.
CVSS Score
10.0
EPSS Score
0.021
Published
2008-02-07


Contact Us

Shodan ® - All rights reserved