Broadcom
broadcom
688 CVEs • 285 products
Products (285)
Click to collapseToggle
Products (285)
Click to collapse
CVEs (688)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perfor...Show more |
Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords. |
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 May 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality. |
Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c. |
Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. |
1Broadcom 1Symantec Siteminder Nov 20, 2024 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argu...Show more |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. |
5Broadcom DebianLinux+2 more9Brocade Fabric Operating System Firmware Communications Cloud Native Core Binding Support FunctionDebian Linux+6 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have...Show more |
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has comp...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 21, 2022 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “factory” account, to...Show more |
1Broadcom 1Layer7 Api Management Oauth Toolkit Jun 17, 2026 Feb 18, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attac...Show more |
1Broadcom 1Xcom Data Transport Jun 17, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privil...Show more |
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. |