Записи EMC
415 опубликованных записей вендора emc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 1,2 %
- Pre-auth RCE
- 51
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-264 Permissions, Privileges, and Access Controls60
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor36
- CWE-20 Improper Input Validation33
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-287 Improper Authentication18
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
415 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2011-0647Готовый эксплойт | The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows reemc · replication manager · CWE-20 | Критическая10,0 | — | 63,7 % | 10 февр. 2011 г. |
52В плане | CVE-2018-1235Proof of concept | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability.emc · recoverpoint · CWE-78 | Критическая9,8 | — | 42,9 % | 29 мая 2018 г. |
52В плане | CVE-2009-2754Proof of concept | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka poribm · informix dynamic server · CWE-189 | Критическая10,0 | — | 40,1 % | 5 мар. 2010 г. |
47В плане | CVE-2014-0644Готовый эксплойт | EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML emc · cloud tiering appliance software · CWE-200 | Высокая7,8 | — | 53,3 % | 16 апр. 2014 г. |
47В плане | CVE-2013-0928Готовый эксплойт | The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to executemc · alphastor · CWE-78 | Критическая9,3 | — | 34,3 % | 21 янв. 2013 г. |
47В плане | CVE-2012-2288Готовый эксплойт | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote aemc · networker · CWE-134 | Критическая9,3 | — | 33,1 % | 4 сент. 2012 г. |
46В плане | CVE-2013-0946Proof of concept | Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary codeemc · alphastor · CWE-119 | Критическая9,3 | — | 28,5 % | 10 мая 2013 г. |
45В плане | CVE-2012-2515Готовый эксплойт | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTemc · captiva quickscan pro · CWE-119 | Критическая9,3 | — | 27,6 % | 4 июл. 2012 г. |
45В плане | CVE-2013-6810Proof of concept | The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Neemc · connectrix manager · CWE-94 | Критическая10,0 | — | 17,0 % | 12 дек. 2013 г. |
44В плане | CVE-2008-3685Эксплойта нет | Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, poemc · documentum applicationxtender workflow manager · CWE-22 | Критическая10,0 | — | 12,9 % | 22 окт. 2009 г. |
43В плане | CVE-2010-0620Proof of concept | Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackeremc · homebase server · CWE-22 | Критическая9,3 | — | 19,5 % | 24 февр. 2010 г. |
43В плане | CVE-2011-2738Эксплойта нет | Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and Ciscocisco · unified service monitor | Критическая10,0 | — | 11,0 % | 19 сент. 2011 г. |
42В плане | CVE-2011-1741Эксплойта нет | Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eemc · documentum eroom · CWE-119 | Критическая10,0 | — | 8,2 % | 19 июл. 2011 г. |
42В плане | CVE-2008-5419Эксплойта нет | Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attacemc · control center · CWE-119 | Критическая10,0 | — | 7,7 % | 10 дек. 2008 г. |
42В плане | CVE-2008-3684Эксплойта нет | Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly emc · documentum applicationxtender · CWE-119 | Критическая10,0 | — | 5,6 % | 22 окт. 2009 г. |
42В плане | CVE-2009-1119Эксплойта нет | Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code viaemc · replistor · CWE-119 | Критическая10,0 | — | 5,4 % | 15 апр. 2009 г. |
42В плане | CVE-2007-5323Эксплойта нет | The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStoremc · replistor · CWE-119 | Критическая10,0 | — | 5,4 % | 10 окт. 2007 г. |
41В плане | CVE-2016-0916Эксплойта нет | EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute emc · networker · CWE-287 | Критическая9,8 | — | 7,7 % | 9 июн. 2016 г. |
41В плане | CVE-2017-4984Эксплойта нет | In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may emc · vnx2 firmware · CWE-77 | Критическая9,8 | — | 6,6 % | 19 июн. 2017 г. |
41В плане | CVE-2017-2767Эксплойта нет | EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.emc · smarts network configuration manager · CWE-287 | Критическая9,8 | — | 5,8 % | 3 февр. 2017 г. |
41В плане | CVE-2018-15764Эксплойта нет | Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggereemc · esrs policy manager | Критическая9,8 | — | 5,3 % | 28 сент. 2018 г. |
41В плане | CVE-2009-0311Эксплойта нет | The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a emc · autostart · CWE-20 | Критическая10,0 | — | 4,7 % | 27 янв. 2009 г. |
41В плане | CVE-2006-3892Эксплойта нет | The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allowemc · networker | Критическая10,0 | — | 4,6 % | 2 мар. 2007 г. |
41В плане | CVE-2015-0545Эксплойта нет | EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute emc · unisphere | Критическая10,0 | — | 4,5 % | 29 июн. 2015 г. |
41В плане | CVE-2015-0546Эксплойта нет | EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid accouemc · unified infrastructure manager\/provisioning · CWE-264 | Критическая10,0 | — | 3,3 % | 17 июн. 2015 г. |
- CVE-2011-064759В плане
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows re
КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %emc · replication manager10 февр. 2011 г.
- CVE-2018-123552В плане
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 43 %emc · recoverpoint29 мая 2018 г.
- CVE-2009-275452В плане
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka por
КритическаяCVSS 10,0Proof of conceptEPSS 40 %ibm · informix dynamic server5 мар. 2010 г.
- CVE-2014-064447В плане
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML
ВысокаяCVSS 7,8Готовый эксплойтEPSS 53 %emc · cloud tiering appliance software16 апр. 2014 г.
- CVE-2013-092847В плане
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execut
КритическаяCVSS 9,3Готовый эксплойтEPSS 34 %emc · alphastor21 янв. 2013 г.
- CVE-2012-228847В плане
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote a
КритическаяCVSS 9,3Готовый эксплойтEPSS 33 %emc · networker4 сент. 2012 г.
- CVE-2013-094646В плане
Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to execute arbitrary code
КритическаяCVSS 9,3Proof of conceptEPSS 29 %emc · alphastor10 мая 2013 г.
- CVE-2012-251545В плане
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HT
КритическаяCVSS 9,3Готовый эксплойтEPSS 28 %emc · captiva quickscan pro4 июл. 2012 г.
- CVE-2013-681045В плане
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Ne
КритическаяCVSS 10,0Proof of conceptEPSS 17 %emc · connectrix manager12 дек. 2013 г.
- CVE-2008-368544В плане
Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, po
КритическаяCVSS 10,0Эксплойта нетEPSS 13 %emc · documentum applicationxtender workflow manager22 окт. 2009 г.
- CVE-2010-062043В плане
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attacker
КритическаяCVSS 9,3Proof of conceptEPSS 19 %emc · homebase server24 февр. 2010 г.
- CVE-2011-273843В плане
Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and Cisco
КритическаяCVSS 10,0Эксплойта нетEPSS 11 %cisco · unified service monitor19 сент. 2011 г.
- CVE-2011-174142В плане
Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum e
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %emc · documentum eroom19 июл. 2011 г.
- CVE-2008-541942В плане
Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attac
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %emc · control center10 дек. 2008 г.
- CVE-2008-368442В плане
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %emc · documentum applicationxtender22 окт. 2009 г.
- CVE-2009-111942В плане
Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %emc · replistor15 апр. 2009 г.
- CVE-2007-532342В плане
The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %emc · replistor10 окт. 2007 г.
- CVE-2016-091641В плане
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %emc · networker9 июн. 2016 г.
- CVE-2017-498441В плане
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %emc · vnx2 firmware19 июн. 2017 г.
- CVE-2017-276741В плане
EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %emc · smarts network configuration manager3 февр. 2017 г.
- CVE-2018-1576441В плане
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggere
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %emc · esrs policy manager28 сент. 2018 г.
- CVE-2009-031141В плане
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %emc · autostart27 янв. 2009 г.
- CVE-2006-389241В плане
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allow
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %emc · networker2 мар. 2007 г.
- CVE-2015-054541В плане
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %emc · unisphere29 июн. 2015 г.
- CVE-2015-054641В плане
EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid accou
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %emc · unified infrastructure manager\/provisioning17 июн. 2015 г.