Broadcom
broadcom
688 CVEs • 285 products
Products (285)
Click to collapseToggle
Products (285)
Click to collapse
CVEs (688)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS v9.1.1 could allow a local authenticated user to perform privilege escalation to root by breaking t...Show more |
1Broadcom 2Advanced Secure Gateway Content AnalysisJun 17, 2026 Jun 1, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. |
1Broadcom 2Advanced Secure Gateway Content AnalysisJun 17, 2026 Jun 1, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. |
1Broadcom 2Advanced Secure Gateway Content AnalysisJun 17, 2026 Jun 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. |
1Broadcom 2Advanced Secure Gateway Content AnalysisJun 17, 2026 Jun 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. |
1Broadcom 1Symantec Siteminder Webagent Jun 17, 2026 May 30, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A user can supply malicious HTML and JavaScript code that will be executed in the client browser |
1Broadcom 1Vmware Nsx T Data Center Jun 17, 2026 May 26, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages. |
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
4Broadcom HaxxNetapp+1 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indi...Show more |
5Broadcom FedoraprojectHaxx+2 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCurl+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first...Show more |
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint. |
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint. |
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint. |
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function. |
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function. |
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint. |
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c. |
1Broadcom 2Symantec Identity Governance And Administration Symantec Identity ManagerJun 17, 2026 Jan 26, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application |
1Broadcom 2Symantec Identity Governance And Administration Symantec Identity ManagerJun 17, 2026 Jan 26, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. |
1Broadcom 2Symantec Identity Governance And Administration Symantec Identity ManagerJun 17, 2026 Jan 26, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. |