EMC records
415 published records for vendor emc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 5 · 1.2%
- Pre-auth RCE
- 51
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-264 Permissions, Privileges, and Access Controls60
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor36
- CWE-20 Improper Input Validation33
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-287 Improper Authentication18
The weakness classes this vendor ships most often: where to look.
CWEAll records
415 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2011-0647Weaponized | The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows reemc · replication manager · CWE-20 | Critical10.0 | — | 63.7% | Feb 10, 2011 |
52Plan | CVE-2018-1235Proof of concept | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability.emc · recoverpoint · CWE-78 | Critical9.8 | — | 42.9% | May 29, 2018 |
52Plan | CVE-2009-2754Proof of concept | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka poribm · informix dynamic server · CWE-189 | Critical10.0 | — | 40.1% | Mar 5, 2010 |
47Plan | CVE-2014-0644Weaponized | EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML emc · cloud tiering appliance software · CWE-200 | High7.8 | — | 53.3% | Apr 16, 2014 |
47Plan | CVE-2013-0928Weaponized | The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to executemc · alphastor · CWE-78 | Critical9.3 | — | 34.3% | Jan 21, 2013 |
47Plan | CVE-2012-2288Weaponized | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote aemc · networker · CWE-134 | Critical9.3 | — | 33.1% | Sep 4, 2012 |
46Plan | CVE-2013-0946Proof of concept | Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary codeemc · alphastor · CWE-119 | Critical9.3 | — | 28.5% | May 10, 2013 |
45Plan | CVE-2012-2515Weaponized | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTemc · captiva quickscan pro · CWE-119 | Critical9.3 | — | 27.6% | Jul 4, 2012 |
45Plan | CVE-2013-6810Proof of concept | The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Neemc · connectrix manager · CWE-94 | Critical10.0 | — | 17.0% | Dec 12, 2013 |
44Plan | CVE-2008-3685No exploit | Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, poemc · documentum applicationxtender workflow manager · CWE-22 | Critical10.0 | — | 12.9% | Oct 22, 2009 |
43Plan | CVE-2010-0620Proof of concept | Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackeremc · homebase server · CWE-22 | Critical9.3 | — | 19.5% | Feb 24, 2010 |
43Plan | CVE-2011-2738No exploit | Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and Ciscocisco · unified service monitor | Critical10.0 | — | 11.0% | Sep 19, 2011 |
42Plan | CVE-2011-1741No exploit | Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eemc · documentum eroom · CWE-119 | Critical10.0 | — | 8.2% | Jul 19, 2011 |
42Plan | CVE-2008-5419No exploit | Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attacemc · control center · CWE-119 | Critical10.0 | — | 7.7% | Dec 10, 2008 |
42Plan | CVE-2008-3684No exploit | Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly emc · documentum applicationxtender · CWE-119 | Critical10.0 | — | 5.6% | Oct 22, 2009 |
42Plan | CVE-2009-1119No exploit | Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code viaemc · replistor · CWE-119 | Critical10.0 | — | 5.4% | Apr 15, 2009 |
42Plan | CVE-2007-5323No exploit | The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStoremc · replistor · CWE-119 | Critical10.0 | — | 5.4% | Oct 10, 2007 |
41Plan | CVE-2016-0916No exploit | EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute emc · networker · CWE-287 | Critical9.8 | — | 7.7% | Jun 9, 2016 |
41Plan | CVE-2017-4984No exploit | In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may emc · vnx2 firmware · CWE-77 | Critical9.8 | — | 6.6% | Jun 19, 2017 |
41Plan | CVE-2017-2767No exploit | EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.emc · smarts network configuration manager · CWE-287 | Critical9.8 | — | 5.8% | Feb 3, 2017 |
41Plan | CVE-2018-15764No exploit | Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggereemc · esrs policy manager | Critical9.8 | — | 5.3% | Sep 28, 2018 |
41Plan | CVE-2009-0311No exploit | The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a emc · autostart · CWE-20 | Critical10.0 | — | 4.7% | Jan 27, 2009 |
41Plan | CVE-2006-3892No exploit | The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allowemc · networker | Critical10.0 | — | 4.6% | Mar 2, 2007 |
41Plan | CVE-2015-0545No exploit | EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute emc · unisphere | Critical10.0 | — | 4.5% | Jun 29, 2015 |
41Plan | CVE-2015-0546No exploit | EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid accouemc · unified infrastructure manager\/provisioning · CWE-264 | Critical10.0 | — | 3.3% | Jun 17, 2015 |
- CVE-2011-064759Plan
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows re
CriticalCVSS 10.0WeaponizedEPSS 64%emc · replication managerFeb 10, 2011
- CVE-2018-123552Plan
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 43%emc · recoverpointMay 29, 2018
- CVE-2009-275452Plan
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka por
CriticalCVSS 10.0Proof of conceptEPSS 40%ibm · informix dynamic serverMar 5, 2010
- CVE-2014-064447Plan
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML
HighCVSS 7.8WeaponizedEPSS 53%emc · cloud tiering appliance softwareApr 16, 2014
- CVE-2013-092847Plan
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execut
CriticalCVSS 9.3WeaponizedEPSS 34%emc · alphastorJan 21, 2013
- CVE-2012-228847Plan
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote a
CriticalCVSS 9.3WeaponizedEPSS 33%emc · networkerSep 4, 2012
- CVE-2013-094646Plan
Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code
CriticalCVSS 9.3Proof of conceptEPSS 29%emc · alphastorMay 10, 2013
- CVE-2012-251545Plan
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HT
CriticalCVSS 9.3WeaponizedEPSS 28%emc · captiva quickscan proJul 4, 2012
- CVE-2013-681045Plan
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Ne
CriticalCVSS 10.0Proof of conceptEPSS 17%emc · connectrix managerDec 12, 2013
- CVE-2008-368544Plan
Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, po
CriticalCVSS 10.0No exploitEPSS 13%emc · documentum applicationxtender workflow managerOct 22, 2009
- CVE-2010-062043Plan
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attacker
CriticalCVSS 9.3Proof of conceptEPSS 19%emc · homebase serverFeb 24, 2010
- CVE-2011-273843Plan
Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and Cisco
CriticalCVSS 10.0No exploitEPSS 11%cisco · unified service monitorSep 19, 2011
- CVE-2011-174142Plan
Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum e
CriticalCVSS 10.0No exploitEPSS 8%emc · documentum eroomJul 19, 2011
- CVE-2008-541942Plan
Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attac
CriticalCVSS 10.0No exploitEPSS 8%emc · control centerDec 10, 2008
- CVE-2008-368442Plan
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly
CriticalCVSS 10.0No exploitEPSS 6%emc · documentum applicationxtenderOct 22, 2009
- CVE-2009-111942Plan
Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via
CriticalCVSS 10.0No exploitEPSS 5%emc · replistorApr 15, 2009
- CVE-2007-532342Plan
The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor
CriticalCVSS 10.0No exploitEPSS 5%emc · replistorOct 10, 2007
- CVE-2016-091641Plan
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute
CriticalCVSS 9.8No exploitEPSS 8%emc · networkerJun 9, 2016
- CVE-2017-498441Plan
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may
CriticalCVSS 9.8No exploitEPSS 7%emc · vnx2 firmwareJun 19, 2017
- CVE-2017-276741Plan
EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.
CriticalCVSS 9.8No exploitEPSS 6%emc · smarts network configuration managerFeb 3, 2017
- CVE-2018-1576441Plan
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggere
CriticalCVSS 9.8No exploitEPSS 5%emc · esrs policy managerSep 28, 2018
- CVE-2009-031141Plan
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a
CriticalCVSS 10.0No exploitEPSS 5%emc · autostartJan 27, 2009
- CVE-2006-389241Plan
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allow
CriticalCVSS 10.0No exploitEPSS 5%emc · networkerMar 2, 2007
- CVE-2015-054541Plan
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute
CriticalCVSS 10.0No exploitEPSS 4%emc · unisphereJun 29, 2015
- CVE-2015-054641Plan
EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid accou
CriticalCVSS 10.0No exploitEPSS 3%emc · unified infrastructure manager\/provisioningJun 17, 2015