
CVE-2008-2241 – CA BrightStor ARCserve Backup caloggerd Arbitrary File Writing Vulnerability
https://notcve.org/view.php?id=CVE-2008-2241
19 May 2008 — Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writing to a startup file or configuration file. Vulnerabilidad de salto de directorio en caloggerd de BrightStor ARCServe Backup 11.0, 11.1 y 11.5, permite a ataca... • http://secunia.com/advisories/30300 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2008-2242 – CA BrightStor ARCserve Backup XDR Parsing Buffer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2008-2242
19 May 2008 — Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function. Múltiples desbordamientos de buffer de las funciones xdr en el servidor de CA BrightStor ARCServe Backup 11.0, 11.1 y 11.5, permiten a atacantes remotos ejecutar código arbitrariamente, tal y como se ha demostrado mediante un desbordamiento de búfer ... • http://secunia.com/advisories/30300 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-1979 – Computer Associates ARCserve Backup Discovery Service Remote - Denial of Service
https://notcve.org/view.php?id=CVE-2008-1979
27 Apr 2008 — The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read. El Discovery Service (casdscvc) en CA ARCserve Backup versión 12.0.5454.0 y anteriores, permite a atacantes remotos causar una denegación de servicio (bloqueo de aplicación) por medio de un paquete con un valor entero largo usado en un incremento al puerto ... • https://www.exploit-db.com/exploits/31707 • CWE-189: Numeric Errors •

CVE-2008-1328
https://notcve.org/view.php?id=CVE-2008-1328
07 Apr 2008 — Buffer overflow in the LGServer service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary code via unspecified "command arguments." Desbordamiento de Búfer del Servicio LGServer de CA ARCserve Backup for Laptops and Desktops versiones de la r11.0 a la r11.5 y Suite 11.1 and 11.2, permite a atacantes remotos ejecutar código de su elección a través de argumentos de comando no especificados. • http://securityreason.com/securityalert/3800 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-1329
https://notcve.org/view.php?id=CVE-2008-1329
07 Apr 2008 — Unspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary commands, related to "insufficient verification of file uploads." Vulnerabilidad no especificada del servicio NetBackup de CA ARCserve Backup for Laptops and Desktops versiones de la r11.0 a la r11.5 y Suite 11.1 and 11.2, permite a atacantes remotos ejecutar comandos de su elección, relacionado con “subidas de archivos s... • http://securityreason.com/securityalert/3800 •

CVE-2007-4620 – Computer Associates - Alert Notification Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-4620
07 Apr 2008 — Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests. Múltiples desbordamientos de buffer basados en pila del servicio Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.4... • https://www.exploit-db.com/exploits/16410 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5325
https://notcve.org/view.php?id=CVE-2007-5325
13 Oct 2007 — Multiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. Múltiples desbordamientos de búfer en (1) el Motor de Mensajería (Message Engine) y (2) AScore.dll de CA BrightStor ARCServe BackUp v9.01 hasta R11.5, y Enterprise Backup r10.5, permiten a atacantes remotos ejecutar código de su elección a través de vectores no especificados. • http://secunia.com/advisories/27192 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5326
https://notcve.org/view.php?id=CVE-2007-5326
13 Oct 2007 — Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors. Múltiples desbordamientos de búfer en (1) RPC y (2) rpcx.dll de CA BrightStor ARCServer BackUp v9.01 hasta R11.5, y Enterprise Backup r10.5, permiten a atacantes remotos ejecutar código de su elección a través de vectores no especificados. • http://osvdb.org/41368 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5327
https://notcve.org/view.php?id=CVE-2007-5327
13 Oct 2007 — Stack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a long argument in the 0x10d opnum. Desbordamiento de búfer basado en pila en el interfaz RPC para el Message Engine (mediasvr.exe) en el CA BrightStor ARCServe BackUp v9.01 hasta la R11.5 y el Enterprise Backup r10.5, permite a atacantes remotos ejecutar código de su elección a través d... • http://ruder.cdut.net/blogview.asp?logID=231 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5328 – CA BrightStor ARCserve Backup Message Engine Insecure Method Exposure Vulnerability
https://notcve.org/view.php?id=CVE-2007-5328
13 Oct 2007 — The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure." El servicio Message Engine RPC en CA BrightStor ARCServe BackUp versión v9.01 hasta r11.5, y Enterprise Backup r10.5, permite a atacantes ejecutar código arbitrario mediante el uso de ciertas "insecure method calls" para modificar el sist... • http://secunia.com/advisories/27192 • CWE-264: Permissions, Privileges, and Access Controls •