networker software vulnerabilities
vulnerabilities.aspcode.net
Searching networker software vulnerabilities
Digital Unix Networker program nsralist has a b
Networker
|
privilege
|
nsralist
|
overflow
|
Digital
|
program
|
allows
|
obtain
|
buffer
|
users
|
local
|
which
|
root
|
Unix
|
has
|
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
Legato NetWorker 6.1 stores log files in the /n
world-readable
|
permissions
|
information
|
/nsr/logs/
|
privileges
|
sensitive
|
NetWorker
|
directory
|
possibly
|
allows
|
stores
|
Legato
|
users
|
which
|
files
|
local
|
gain
|
read
|
log
|
Legato NetWorker 6.1 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges.
Legato NetWorker 6.1 stores passwords in plaint
privileges
|
plaintext
|
daemonlog
|
passwords
|
NetWorker
|
password
|
reading
|
Legato
|
allows
|
stores
|
users
|
which
|
local
|
file
|
gain
|
Legato NetWorker 6.1 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file.
EMC Legato NetWorker, Sun Solstice Backup 6.0 a
authentication
|
privileges
|
Enterprise
|
NetWorker
|
attackers
|
AUTH_UNIX
|
spoofing
|
username
|
Solstice
|
StorEdge
|
through
|
Legato
|
allows
|
remote
|
Backup
|
bypass
|
relies
|
which
|
rely
|
gain
|
user
|
UID
|
Sun
|
EMC
|
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
EMC Legato NetWorker, Solstice Backup 6.0 and 6
authentication
|
Enterprise
|
privileges
|
attackers
|
NetWorker
|
modifying
|
properly
|
StorEdge
|
Solstice
|
through
|
allows
|
remote
|
tokens
|
Backup
|
Legato
|
verify
|
which
|
token
|
gain
|
not
|
EMC
|
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
The Legato PortMapper in EMC Legato NetWorker,
Enterprise
|
pmap_unset
|
PortMapper
|
NetWorker
|
attackers
|
StorEdge
|
restrict
|
commands
|
Solstice
|
pmap_set
|
through
|
Backup
|
remote
|
Legato
|
allows
|
access
|
which
|
does
|
EMC
|
Sun
|
not
|
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
Multiple heap-based buffer overflows in EMC Leg
heap-based
|
overflows
|
NetWorker
|
Multiple
|
Legato
|
buffer
|
before
|
71x
|
EMC
|
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
nsrd.exe in EMC Legato NetWorker 7.1.x before 7
NetWorker
|
nsrdexe
|
before
|
Legato
|
EMC
|
71x
|
nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.
The Management Console server in EMC NetWorker
Management
|
NetWorker
|
Console
|
server
|
EMC
|
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands.
Stack-based buffer overflow in the NetWorker Re
Stack-based
|
NetWorker
|
overflow
|
Service
|
Remote
|
buffer
|
Exec
|
Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd."
Software vulnerabilities results 1 to 11 of 11
Page:
1