CVE-2008-1786
https://notcve.org/view.php?id=CVE-2008-1786
The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments. El control ActiveX DSM gui_cm_ctrls (archivo gui_cm_ctrls.ocx), tal y como es usado en distintos productos de CA, incluyendo a BrightStor ARCServe Backup for Laptops and Desktops versión r11.5, Desktop Management Suite versiones r11.1 hasta r11.2 C2; Unicenter versiones r11.1 hasta r11.2 C2; y Desktop and Server Management versiones r11.1 hasta r11.2 C2, permite a los atacantes remotos ejecutar código arbitrario por medio de argumentos de función diseñados. • http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/16/ca-dsm-gui-cm-ctrls-activex-control-vulnerability.aspx http://secunia.com/advisories/29837 http://www.kb.cert.org/vuls/id/684883 http://www.securityfocus.com/archive/1/490959/100/0/threaded http://www.securityfocus.com/bid/28809 http://www.securitytracker.com/id?1019872 http://www.vupen.com/english/advisories/2008/1249/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41853 https://support.ca.com/ • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2008-1472 – CA BrightStor ARCserve Backup - 'AddColumn()' ActiveX Buffer Overflow
https://notcve.org/view.php?id=CVE-2008-1472
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method. Un desbordamiento de búfer en la región stack de la memoria en el control ActiveX ListCtrl (ListCtrl.ocx), como es usado en varios productos de CA, incluyendo BrightStor ARCserve Backup versión R11.5, Desktop Management Suite versiones r11.1 hasta r11.2 y productos Unicenter versiones r11.1 hasta r11. 2, permite a los atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (bloqueo) por medio de un argumento largo en el método AddColumn. The CA BrightStor ARCserve Backup ActiveX control (ListCtrl.ocx) is vulnerable to a stack-based buffer overflow. By passing an overly long argument to the AddColumn() method, a remote attacker could overflow a buffer and execute arbitrary code on the system. • https://www.exploit-db.com/exploits/16577 https://www.exploit-db.com/exploits/5264 http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx http://secunia.com/advisories/29408 http://www.securityfocus.com/archive/1/489893/100/0/threaded http://www.securityfocus.com/archive/1/490263/100/0/threaded http://www.securityfocus.com/bid/28268 http://www.securitytracker.com/id?1019617 http://www.vupen.com/english/advisories/2008/0902/references https://exchange. • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •