Broadcom
broadcom
688 CVEs • 285 products
Products (285)
Click to collapseToggle
Products (285)
Click to collapse
CVEs (688)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Broadcom LinuxNetapp19A250 Firmware A700s FirmwareAff 500f Firmware+16 moreJun 17, 2026 Nov 23, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. |
1Broadcom 1Unified Infrastructure Management Jun 17, 2026 Nov 23, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges. |
2Broadcom Vmware2Cloud Foundation Vmware Nsx T Data CenterJun 17, 2026 Oct 20, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positio...Show more |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Oct 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Oct 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell var...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log fil...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated...Show more |
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process. |
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Sep 25, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access t...Show more |
2Broadcom Pivotal Software2Rabbitmq Rabbitmq ServerJun 17, 2026 Aug 31, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation direc...Show more |
3Broadcom NetappOpenbsd9A700s Firmware Active Iq Unified ManagerFabric Operating System+6 moreJun 17, 2026 Jul 24, 2020 N/A· v4 7.4 HIGH· v3 6.8 MEDIUM· v2 scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omi...Show more |
1Broadcom 1Brocade Network Advisor Jun 17, 2026 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credential...Show more |
2Broadcom Pivotal Software2Spring Batch Spring BatchSep 1, 2026 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more |