CA Technologies, now a Broadcom subsidiary, maintains a moderately broad portfolio of enterprise backup, security, and systems-management products that serve large organizations, including BrightStor ArcServe Backup, eTrust Secure Content Manager, and various protection suites. Its vulnerability disclosures recur across input-handling and memory-safety weakness classes—particularly cross-site scripting, improper input validation, and buffer-boundary issues—that are characteristic of large, legacy enterprise software managing sensitive data and system access. The vendor's exposures frequently acquire public exploit code, making its advisories operationally significant despite a measured severity profile. Defenders should prioritize this vendor's updates for internet-reachable backup and security appliances, as these products often hold administrative credentials and control over critical infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by CA Technologies - A Broadcom Company over time
Of all the CVEs published by CA Technologies - A Broadcom Company as a CNA, 22.0% affect products that CA Technologies - A Broadcom Company develops as a vendor.
Of all the CVEs published that affect products developed by CA Technologies - A Broadcom Company, 14.5% are self-published by CA Technologies - A Broadcom Company as a CNA.
Signals from CVEs in this vendor scope (138 CVEs).
138 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4397HIGH Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to exec | Oct 14, 2008 | 10.0 | 84 | NO | YES |
CVE-2005-2668HIGH Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arb | Aug 23, 2005 | 10.0 | 84 | NO | YES |
CVE-2007-2139HIGH Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 throu | Apr 25, 2007 | 10.0 | 83 | NO | YES |
CVE-2007-5003HIGH Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrar | Oct 1, 2007 | 10.0 | 81 | NO | YES |
CVE-2006-6076HIGH Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code | Nov 24, 2006 | 10.0 | 80 | NO | YES |
CVE-2006-5143HIGH Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Se | Oct 10, 2006 | 7.5 | 78 | NO | YES |
CVE-2011-3011MEDIUM BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, vi | Aug 15, 2011 | 5.0 | 74 | NO | YES |
CVE-2005-1272HIGH Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code v | Aug 5, 2005 | 7.5 | 74 | NO | YES |
CVE-2007-2864HIGH Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary | Jun 6, 2007 | 9.3 | 73 | NO | YES |
CVE-2004-0932HIGH McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via | Jan 27, 2005 | 7.5 | 71 | NO | YES |
Signals from CVEs in this vendor scope (138 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by CA Technologies - A Broadcom Company.
Media articles that mention a CVE ID that affects a product developed by CA Technologies - A Broadcom Company — matched by CVE ID, not by vendor name.