Skip to content
Noroxi

bacula records

7 published records for vendor bacula.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
85.7%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database

    CriticalCVSS 9.8Proof of conceptEPSS 23%

    bacula · bacula-webMar 7, 2018

  • SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.

    HighCVSS 8.1Proof of conceptEPSS 1%

    bacula · bacula-webJul 29, 2025

  • CVE-2014-8295
    31Monitor

    SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid para

    HighCVSS 7.5Proof of conceptEPSS 2%

    bacula · bacula-webOct 15, 2014

  • CVE-2008-5373
    27Monitor

    mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### t

    MediumCVSS 6.9No exploitEPSS 0%

    bacula · baculaDec 8, 2008

  • CVE-2007-5626
    22Monitor

    make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleart

    MediumCVSS 5.5No exploitEPSS 0%

    bacula · baculaOct 23, 2007

  • CVE-2012-4430
    17Monitor

    The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticate

    MediumCVSS 4.0No exploitEPSS 3%

    bacula · baculaOct 10, 2012

  • CVE-2005-2995
    14Monitor

    bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autocon

    LowCVSS 3.6No exploitEPSS 0%

    bacula · baculaSep 20, 2005