cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2009-3027,https://securityvulnerability.io/vulnerability/CVE-2009-3027,,"VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.",Symantec,"Veritas Cluster Server One,Veritas Storage Foundation For Oracle Real Application Cluster,Veritas Storage Foundation Cluster File System,Veritas Storage Foundation Manager,Veritas Cluster Server,Veritas Netbackup Operations Manager,Veritas Storage Foundation For Windows High Availability,Veritas Storage Foundation,Veritas Micromeasure,Backup Exec Continuous Protection Server,Veritas Storage Foundation For High Availability,Veritas Storage Foundation For Sybase,Veritas Storage Foundation For Db2,Veritas Command Central Storage,Veritas Application Director,Veritas Command Central Storage Change Manager,Veritas Storage Foundation For Oracle,Veritas Cluster Server Management Console,Veritas Command Central Enterprise Reporter,Veritas Storage Foundation Cluster File System For Oracle Rac,Veritas Netbackup Reporter,Veritas Backup Exec,Veritas Storae Foundation",,,0.8903599977493286,false,,false,false,false,,,false,false,,2009-12-11T16:00:00.000Z,0 CVE-2008-5407,https://securityvulnerability.io/vulnerability/CVE-2008-5407,,"Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors.",Symantec,Backup Exec For Windows Server,,,0.012120000086724758,false,,false,false,false,,,false,false,,2008-12-10T06:44:00.000Z,0 CVE-2008-5408,https://securityvulnerability.io/vulnerability/CVE-2008-5408,,"Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2008-5407.",Symantec,Backup Exec For Windows Server,,,0.052080001682043076,false,,false,false,false,,,false,false,,2008-12-10T06:44:00.000Z,0 CVE-2007-6016,https://securityvulnerability.io/vulnerability/CVE-2007-6016,,"Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states ""Authenticated user involvement required,"" but authentication is not needed to attack a client machine that loads this control.",Symantec,Backup Exec For Windows Server,,,0.9307299852371216,false,,false,false,false,,,false,false,,2008-02-29T19:00:00.000Z,0 CVE-2007-6017,https://securityvulnerability.io/vulnerability/CVE-2007-6017,,"The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary files, via string values of the (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, and (19) _MonthText11 properties. NOTE: the vendor states ""Authenticated user involvement required,"" but authentication is not needed to attack a client machine that loads this control.",Symantec,Backup Exec For Windows Server,,,0.6901000142097473,false,,false,false,false,,,false,false,,2008-02-29T19:00:00.000Z,0