Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)7.0%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise Backup13/10/200716/6/2026
The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."
ModificadaAlta (9.3)8.9%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Desktop Management SuiteCA Protection Suites1/10/200716/6/2026
Integer overflow in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to execute arbitrary code via a long username and a certain "useless" password.
ModificadaAlta (10)67%💥 ExploitBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Desktop Management SuiteCA Protection Suites1/10/200716/6/2026
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo…
ModificadaAlta (10)21%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Desktop Management SuiteCA Protection Suites1/10/200716/6/2026
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.
ModificadaAlta (10)5.2%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Desktop Management SuiteCA Protection Suites1/10/200716/6/2026
Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the…
ModificadaMedia (4.3)3.6%—Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+1926/7/200716/6/2026
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
ModificadaAlta (9.3)14%—Broadcom Alert Notification ServerBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupCA Anti-virus FOR THE Enterprise+418/7/200716/6/2026
Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers…
ModificadaAlta (10)59%💥 ExploitBroadcom Brightstor Arcserve Backup Laptops Desktops14/6/200716/6/2026
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5)…
ModificadaAlta (9.3)50%💥 ExploitBroadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+96/6/200716/6/2026
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.
ModificadaAlta (10)23%—Broadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Common Services+26/6/200716/6/2026
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.
ModificadaAlta (7.8)12%💥 ExploitCA Brightstor Arcserve Backup21/5/200716/6/2026
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.
ModificadaAlta (10)78%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Business Protection SuiteBroadcom Server Protection SuiteCA Brightstor Arcserve Backup+125/4/200716/6/2026
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to…
ModificadaAlta (7.1)15%💥 ExploitBroadcom Brightstor Arcserve BackupCA Brightstor Arcserve Backup31/3/200716/6/2026
The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.
ModificadaBaja (2.1)0.91%—Broadcom Brightstor Arcserve Backup16/3/200716/6/2026
The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function.
ModificadaAlta (10)14%—Broadcom Brightstor Arcserve Backup16/3/200716/6/2026
The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC procedure arguments, which result in memory corruption, a different vulnerability than CVE-2006-6076.
ModificadaMedia (5)11%💥 ExploitBroadcom Brightstor Arcserve Backup7/2/200716/6/2026
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or…
ModificadaAlta (7.8)2.8%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+13/2/200716/6/2026
LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.
ModificadaAlta (7.8)3.2%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Business Protection SuiteBroadcom Desktop Management SuiteBroadcom Desktop Protection Suite+13/2/200716/6/2026
LGSERVER.EXE in BrightStor ARCserve Backup for Laptops & Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read.
ModificadaAlta (10)79%💥 ExploitBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Management Suite+123/1/200716/6/2026
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port…
ModificadaAlta (10)15%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupCA Protection Suites16/1/200716/6/2026
Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe String Handling Overflow," a…
ModificadaAlta (10)17%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupCA Protection Suites16/1/200716/6/2026
Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe Overflow," a different…
ModificadaAlta (7.5)70%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection Suite11/1/200716/6/2026
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC…
ModificadaAlta (7.5)20%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupBroadcom Business Protection Suite11/1/200716/6/2026
The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.
ModificadaAlta (10)30%💥 ExploitBroadcom Brightstor Arcserve Backup Server31/12/200616/6/2026
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is…
ModificadaAlta (7.5)2.6%—Arcserve BrightstorBroadcom Cleverpath PortalCleverpath Aion BPMCleverpath Portal+720/12/200616/6/2026
Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are…
Orbitaley — Vulnerabilidades