Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.
2007-07-18T23:30:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | broadcom | alert_notification_server | * | Yes |
| Application | broadcom | brightstor_arcserve_backup | 9.01 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.1 | Yes |
| Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
| Application | broadcom | brightstor_enterprise_backup | 10.5 | Yes |
| Application | ca | anti-virus_for_the_enterprise | 8 | Yes |
| Application | ca | brightstor_arcserve_backup | 11 | Yes |
| Application | ca | brightstor_arcserve_client | * | Yes |
| Application | ca | protection_suites | r3 | Yes |
| Application | ca | threat_manager | 8 | Yes |