3 results (0.004 seconds)

CVSS: 9.3EPSS: 29%CPEs: 30EXPL: 0

The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments. El control ActiveX DSM gui_cm_ctrls (archivo gui_cm_ctrls.ocx), tal y como es usado en distintos productos de CA, incluyendo a BrightStor ARCServe Backup for Laptops and Desktops versión r11.5, Desktop Management Suite versiones r11.1 hasta r11.2 C2; Unicenter versiones r11.1 hasta r11.2 C2; y Desktop and Server Management versiones r11.1 hasta r11.2 C2, permite a los atacantes remotos ejecutar código arbitrario por medio de argumentos de función diseñados. • http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx http://secunia.com/advisories/29837 http://www.kb.cert.org/vuls/id/684883 http://www.securityfocus.com/archive/1/490959/100/0/threaded http://www.securityfocus.com/bid/28809 http://www.securitytracker.com/id?1019872 http://www.vupen.com/english/advisories/2008/1249/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41853 https://support.ca.com/ • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.3EPSS: 89%CPEs: 8EXPL: 0

Buffer overflow in the LGServer service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary code via unspecified "command arguments." Desbordamiento de Búfer del Servicio LGServer de CA ARCserve Backup for Laptops and Desktops versiones de la r11.0 a la r11.5 y Suite 11.1 and 11.2, permite a atacantes remotos ejecutar código de su elección a través de argumentos de comando no especificados. • http://securityreason.com/securityalert/3800 http://www.securityfocus.com/archive/1/490463/100/0/threaded http://www.securityfocus.com/bid/28616 http://www.securitytracker.com/id?1019788 http://www.vupen.com/english/advisories/2008/1104/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41641 https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173105 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 10.0EPSS: 1%CPEs: 8EXPL: 0

Unspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary commands, related to "insufficient verification of file uploads." Vulnerabilidad no especificada del servicio NetBackup de CA ARCserve Backup for Laptops and Desktops versiones de la r11.0 a la r11.5 y Suite 11.1 and 11.2, permite a atacantes remotos ejecutar comandos de su elección, relacionado con “subidas de archivos sin suficiente verificacion” • http://securityreason.com/securityalert/3800 http://www.securityfocus.com/archive/1/490463/100/0/threaded http://www.securityfocus.com/bid/28616 http://www.securitytracker.com/id?1019788 http://www.vupen.com/english/advisories/2008/1104/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41642 https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173105 •