Broadcom records
698 published records for vendor broadcom.
Researcher profile
- Entered KEV
- 4 · 0.6%
- Weaponized
- 25 · 3.6%
- Pre-auth RCE
- 98
- With a fix record
- 24.8%
- Median publish → KEV
- 760 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')46
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer37
- CWE-20 Improper Input Validation25
- CWE-532 Insertion of Sensitive Information into Log File19
- CWE-125 Out-of-bounds Read17
- CWE-287 Improper Authentication14
The weakness classes this vendor ships most often: where to look.
CWEAll records
698 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2018-1273Weaponized | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Critical9.8 | KEV | 97.0% | Apr 11, 2018 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
68This week | CVE-2010-0425Weaponized | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, wapache · http server | Critical10.0 | — | 94.2% | Mar 5, 2010 |
67This week | CVE-2011-1653Weaponized | Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attabroadcom · total defense · CWE-89 | Critical10.0 | — | 88.7% | Apr 18, 2011 |
64This week | CVE-2008-4397Weaponized | Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 throuca · arcserve backup · CWE-20 | Critical10.0 | — | 80.5% | Oct 14, 2008 |
64This week | CVE-2007-0449Weaponized | Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup rbroadcom · brightstor arcserve backup laptops desktops · CWE-119 | Critical10.0 | — | 79.4% | Jan 23, 2007 |
64This week | CVE-2025-1976Weaponized | Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6broadcom · fabric operating system · CWE-94 | High8.6 | KEV | 0.7% | Apr 23, 2025 |
63This week | CVE-2007-2139Weaponized | Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used ca · brightstor arcserve backup | Critical10.0 | — | 78.0% | Apr 25, 2007 |
63This week | CVE-2005-2668Weaponized | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_ca · etrust admin | Critical10.0 | — | 75.2% | Aug 23, 2005 |
62This week | CVE-2020-8012Weaponized | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (cbroadcom · unified infrastructure management · CWE-120 | Critical9.8 | — | 77.4% | Feb 18, 2020 |
61This week | CVE-2006-6076Weaponized | Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remca · brightstor arcserve backup | Critical10.0 | — | 70.9% | Nov 24, 2006 |
61This week | CVE-2005-0260Weaponized | Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbibroadcom · brightstor arcserve backup | Critical10.0 | — | 69.7% | May 2, 2005 |
60This week | CVE-2007-5003Weaponized | Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 alca · protection suites · CWE-119 | Critical10.0 | — | 67.2% | Oct 1, 2007 |
59Plan | CVE-2022-23305Proof of concept | SQL injection in JDBC Appender in Apache Log4j V1apache · log4j · CWE-89 | Critical9.8 | — | 66.5% | Jan 18, 2022 |
59Plan | CVE-2007-5082Weaponized | Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote atbroadcom · brightstor hierarchical storage manager · CWE-119 | Critical10.0 | — | 63.5% | Oct 1, 2007 |
58Plan | CVE-2022-2068No exploit | The c_rehash script allows command injectionopenssl · openssl · CWE-78 | High7.3 | — | 95.4% | Jun 21, 2022 |
58Plan | CVE-2017-9417Proof of concept | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.broadcom · bcm43xx wi-fi chipset firmware | Critical9.8 | — | 64.0% | Jun 4, 2017 |
58Plan | CVE-2007-3216Weaponized | Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 albroadcom · brightstor arcserve backup laptops desktops · CWE-119 | Critical10.0 | — | 59.2% | Jun 14, 2007 |
54Plan | CVE-2005-2535Weaponized | Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commandbroadcom · arcserve backup 2000 | High7.5 | — | 80.9% | Aug 10, 2005 |
54Plan | CVE-2006-5143Weaponized | Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r1ca · brightstor arcserve backup · CWE-119 | High7.5 | — | 79.5% | Oct 10, 2006 |
54Plan | CVE-2022-23302No exploit | Deserialization of untrusted data in JMSSink in Apache Log4j 1.xapache · log4j · CWE-502 | High8.8 | — | 63.6% | Jan 18, 2022 |
54Plan | CVE-2020-8010Weaponized | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the rbroadcom · unified infrastructure management | Critical9.8 | — | 50.7% | Feb 18, 2020 |
54Plan | CVE-2004-1812No exploit | Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackerbroadcom · unicenter tng | Critical10.0 | — | 45.2% | Dec 31, 2004 |
52Plan | CVE-2007-4620Weaponized | Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0ca · brightstor arcserve backup · CWE-119 | Critical9.0 | — | 52.3% | Apr 7, 2008 |
- CVE-2018-127398Now
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
CriticalCVSS 9.8KEVWeaponizedEPSS 97%broadcom · spring data commonsApr 11, 2018
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2010-042568This week
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w
CriticalCVSS 10.0WeaponizedEPSS 94%apache · http serverMar 5, 2010
- CVE-2011-165367This week
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote atta
CriticalCVSS 10.0WeaponizedEPSS 89%broadcom · total defenseApr 18, 2011
- CVE-2008-439764This week
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 throu
CriticalCVSS 10.0WeaponizedEPSS 81%ca · arcserve backupOct 14, 2008
- CVE-2007-044964This week
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r
CriticalCVSS 10.0WeaponizedEPSS 79%broadcom · brightstor arcserve backup laptops desktopsJan 23, 2007
- CVE-2025-197664This week
Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
HighCVSS 8.6KEVWeaponizedEPSS 1%broadcom · fabric operating systemApr 23, 2025
- CVE-2007-213963This week
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used
CriticalCVSS 10.0WeaponizedEPSS 78%ca · brightstor arcserve backupApr 25, 2007
- CVE-2005-266863This week
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_
CriticalCVSS 10.0WeaponizedEPSS 75%ca · etrust adminAug 23, 2005
- CVE-2020-801262This week
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (c
CriticalCVSS 9.8WeaponizedEPSS 77%broadcom · unified infrastructure managementFeb 18, 2020
- CVE-2006-607661This week
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows rem
CriticalCVSS 10.0WeaponizedEPSS 71%ca · brightstor arcserve backupNov 24, 2006
- CVE-2005-026061This week
Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbi
CriticalCVSS 10.0WeaponizedEPSS 70%broadcom · brightstor arcserve backupMay 2, 2005
- CVE-2007-500360This week
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 al
CriticalCVSS 10.0WeaponizedEPSS 67%ca · protection suitesOct 1, 2007
- CVE-2022-2330559Plan
SQL injection in JDBC Appender in Apache Log4j V1
CriticalCVSS 9.8Proof of conceptEPSS 67%apache · log4jJan 18, 2022
- CVE-2007-508259Plan
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote at
CriticalCVSS 10.0WeaponizedEPSS 63%broadcom · brightstor hierarchical storage managerOct 1, 2007
- CVE-2022-206858Plan
The c_rehash script allows command injection
HighCVSS 7.3No exploitEPSS 95%openssl · opensslJun 21, 2022
- CVE-2017-941758Plan
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
CriticalCVSS 9.8Proof of conceptEPSS 64%broadcom · bcm43xx wi-fi chipset firmwareJun 4, 2017
- CVE-2007-321658Plan
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 al
CriticalCVSS 10.0WeaponizedEPSS 59%broadcom · brightstor arcserve backup laptops desktopsJun 14, 2007
- CVE-2005-253554Plan
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary command
HighCVSS 7.5WeaponizedEPSS 81%broadcom · arcserve backup 2000Aug 10, 2005
- CVE-2006-514354Plan
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r1
HighCVSS 7.5WeaponizedEPSS 80%ca · brightstor arcserve backupOct 10, 2006
- CVE-2022-2330254Plan
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
HighCVSS 8.8No exploitEPSS 64%apache · log4jJan 18, 2022
- CVE-2020-801054Plan
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the r
CriticalCVSS 9.8WeaponizedEPSS 51%broadcom · unified infrastructure managementFeb 18, 2020
- CVE-2004-181254Plan
Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attacker
CriticalCVSS 10.0No exploitEPSS 45%broadcom · unicenter tngDec 31, 2004
- CVE-2007-462052Plan
Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0
CriticalCVSS 9.0WeaponizedEPSS 52%ca · brightstor arcserve backupApr 7, 2008