← Back

Broadcom

broadcom

645 CVEs • 275 products

Products (275)

Click to collapse
Toggle
Tcpreplay
tcpreplay
Sannav
sannav
Inoculateit
inoculateit
Etrust Admin
etrust_admin
Unicenter Tng
unicenter_tng
Total Defense
total_defense
Adviseit
adviseit
Anti Virus
anti-virus
Siteminder
siteminder
Ehealth
ehealth
Vmware Nsx
vmware_nsx
Messaging
messaging
Anti Spyware
anti-spyware
Spectrum
spectrum

CVEs (645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Fabric Operating System
Jun 17, 2026
Sep 25, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access t...Show more
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.Show less
2Broadcom
Pivotal Software
2Rabbitmq
Rabbitmq Server
Jun 17, 2026
Aug 31, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation direc...Show more
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.Show less
3Broadcom
NetappOpenbsd
9A700s Firmware
Active Iq Unified ManagerFabric Operating System+6 more
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.4 HIGH· v3
6.8 MEDIUM· v2
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omi...Show more
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."Show less
1Broadcom
1Brocade Network Advisor
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credential...Show more
A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.Show less
21Asus
BroadcomCanon+18 more
2175020 Z4a69a
5030 M2u92b5030 Z4a70a+214 more
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.Show less
4Broadcom
DebianDocker+1 more
4Debian Linux
EngineFedora+1 more
Jun 17, 2026
Jun 2, 2020
N/A· v4
6.0 MEDIUM· v3
6.0 MEDIUM· v2
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive in...Show more
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.Show less
5Broadcom
CanonicalFedoraproject+2 more
6Balsa
Cloud BackupFabric Operating System+3 more
Jun 17, 2026
May 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.Show less
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
May 8, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
8Apple
BroadcomCanonical+5 more
18Brocade Fabric Operating System
Cloud BackupDebian Linux+15 more
Jun 17, 2026
Apr 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
10Broadcom
DebianFedoraproject+7 more
26Active Iq Unified Manager
Application ServerDebian Linux+23 more
Jun 17, 2026
Apr 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"...Show more
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).Show less
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.
1Broadcom
2Advanced Secure Gateway
Symantec Proxysg
Jun 17, 2026
Apr 10, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and...Show more
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.Show less