← Back

Emc

emc

413 CVEs • 186 products

Products (186)

Click to collapse
Toggle
Networker
networker
Isilon Onefs
isilon_onefs
Avamar Server
avamar_server
Documentum D2
documentum_d2
Avamar
avamar
Vipr Srm
vipr_srm
Recoverpoint
recoverpoint
Watch4net
watch4net
Appsync
appsync
Scaleio
scaleio
Replistor
replistor
Autostart
autostart
Alphastor
alphastor
Diskxtender
diskxtender
Unisphere
unisphere
Vnx2 Firmware
vnx2_firmware
Vnx1 Firmware
vnx1_firmware
Eroom
eroom
Retrospect
retrospect
Vmware
vmware
Atmos
atmos
Task Space
task_space
Rsa Archer
rsa_archer
Vmware Server
vmware_server
Vmware Player
vmware_player
Disk Library
disk_library

CVEs (413)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emc
1Avamar
Apr 29, 2026
Oct 31, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to the proxy client.
1Emc
1Networker Module For Microsoft Applications
Apr 29, 2026
Oct 18, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communic...Show more
The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.Show less
1Emc
1Networker Module For Microsoft Applications
Apr 29, 2026
Oct 18, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext...Show more
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.Show less
1Emc
1Rsa Adaptive Authentication On Premise
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
2.9 LOW· v2
Unspecified vulnerability in EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 before SP3 P3 allows remote attackers to obtain sensitive information via unknown vectors.
1Emc
2Rsa Authentication Agent
Rsa Authentication Client
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
8.5 HIGH· v2
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to...Show more
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.Show less
1Emc
1Networker
Apr 29, 2026
Sep 4, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via format string specifiers in a message.
1Emc
2Cloud Tiering Appliance
Cloud Tiering Appliance Virtual Edition
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted...Show more
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted file during the authentication phase.Show less
1Emc
2Applicationxtender Desktop
Applicationxtender Web Access .net
Apr 29, 2026
Aug 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via unspecified vectors.
2Emc
Iomega
4Home Media Network Hard Drive
IconnectLifeline+1 more
Apr 29, 2026
Aug 16, 2012
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Iomega Home Media Network Hard Drive with EMC Lifeline firmware before 2.104, Home Media Network Hard Drive Cloud Edition with EMC Lifeline firmware before 3.2.3.15290, iConnect with EMC Lifeline firmware before 2.5....Show more
The Iomega Home Media Network Hard Drive with EMC Lifeline firmware before 2.104, Home Media Network Hard Drive Cloud Edition with EMC Lifeline firmware before 3.2.3.15290, iConnect with EMC Lifeline firmware before 2.5.26.18966, and StorCenter with EMC Lifeline firmware before 2.0.18.23122, 2.1.x before 2.1.42.18967, and 3.x before 3.2.3.15290 allow remote authenticated users to read or modify data on arbitrary remote shares via unspecified vectors.Show less
1Emc
3Celerra Network Server
VnxVnxe
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, wh...Show more
EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request.Show less
2Emc
Rsa
3Authentication Manager
Rsa Authentication ManagerSecurid Appliance
Apr 29, 2026
Jul 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, rel...Show more
EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability."Show less
2Emc
Rsa
3Authentication Manager
Rsa Authentication ManagerSecurid Appliance
Apr 29, 2026
Jul 13, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and c...Show more
Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
2Emc
Rsa
3Authentication Manager
Rsa Authentication ManagerSecurid Appliance
Apr 29, 2026
Jul 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
2Emc
Ge
7Captiva Quickscan Pro
Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch Execution+4 more
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EM...Show more
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; GE Intelligent Platforms Proficy HMI/SCADA iFIX 5.0 and 5.1; GE Intelligent Platforms Proficy Pulse 1.0; GE Intelligent Platforms Proficy Batch Execution 5.6; GE Intelligent Platforms SI7 I/O Driver 7.20 through 7.42; and other products, allow remote attackers to execute arbitrary code via a long string in the second argument to the (1) JumpMappedID or (2) JumpURL method.Show less
1Emc
1Autostart
Apr 29, 2026
Jun 1, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via crafted packets.
1Emc
1Documentum Information Rights Management
Apr 29, 2026
May 14, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters i...Show more
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many "batch begin untethered" commands.Show less
1Emc
1Documentum Information Rights Management
Apr 29, 2026
May 14, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data t...Show more
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.Show less
1Emc
1Data Protection Advisor
Apr 29, 2026
Apr 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size fi...Show more
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size field.Show less
1Emc
1Data Protection Advisor
Apr 29, 2026
Apr 20, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHE...Show more
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.Show less
1Emc
1Documentum Eroom
Apr 29, 2026
Mar 15, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.