Filtered by vendor Veritas
Subscribe
Total
140 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-44924 | 1 Veritas | 1 Infoscale Operations Manager | 2026-07-23 | N/A | 5.4 MEDIUM |
| InfoScale VIOM 9.1.3 allows XSS. | |||||
| CVE-2026-44923 | 1 Veritas | 1 Infoscale Operations Manager | 2026-07-23 | N/A | 6.5 MEDIUM |
| SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | |||||
| CVE-2026-44925 | 1 Veritas | 1 Infoscale Operations Manager | 2026-07-23 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge. | |||||
| CVE-2024-53915 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53914 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53913 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53912 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53911 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53910 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-53909 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |||||
| CVE-2024-52945 | 1 Veritas | 1 Netbackup | 2026-06-17 | N/A | 7.8 HIGH |
| An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context. | |||||
| CVE-2024-52944 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 5.4 MEDIUM |
| An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |||||
| CVE-2024-52943 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 5.4 MEDIUM |
| An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |||||
| CVE-2024-52942 | 1 Veritas | 1 Enterprise Vault | 2026-06-17 | N/A | 5.4 MEDIUM |
| An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |||||
| CVE-2024-47854 | 1 Veritas | 1 Data Insight | 2026-06-17 | N/A | 6.1 MEDIUM |
| An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user. | |||||
| CVE-2024-33673 | 1 Veritas | 1 Backup Exec | 2026-06-17 | N/A | 7.8 HIGH |
| An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path. | |||||
| CVE-2024-33672 | 1 Veritas | 1 Netbackup | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-33671 | 1 Veritas | 1 Backup Exec | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-28222 | 1 Veritas | 2 Netbackup, Netbackup Appliance | 2026-06-17 | N/A | 9.8 CRITICAL |
| In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file. | |||||
| CVE-2024-27283 | 1 Veritas | 1 Ediscovery Platform | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to arbitrary locations on the server on which the application is installed. | |||||
