10
CVE-2007-5003
- EPSS 67.2%
- Veröffentlicht 01.10.2007 20:17:00
- Zuletzt bearbeitet 16.06.2026 22:45:16
- Erkennungen
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Brightstor Arcserve Backup Laptops Desktops Version 4.0
Broadcom ≫ Brightstor Arcserve Backup Laptops Desktops Version 11.0
Broadcom ≫ Brightstor Arcserve Backup Laptops Desktops Version 11.1
Broadcom ≫ Brightstor Arcserve Backup Laptops Desktops Version 11.1 Update sp1
Broadcom ≫ Brightstor Arcserve Backup Laptops Desktops Version 11.5
Broadcom ≫ Desktop Management Suite Version 11.0
Broadcom ≫ Desktop Management Suite Version 11.1
Broadcom ≫ Desktop Management Suite Version 11.2
Ca ≫ Protection Suites Version r2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 67.2% | 0.992 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=599
http://research.eeye.com/html/advisories/published/AD20070920.html
http://secunia.com/advisories/25606
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.asp
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006
http://www.securityfocus.com/archive/1/480252/100/100/threaded
http://www.securityfocus.com/bid/24348
http://www.securitytracker.com/id?1018728
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35674