Computer Associates' vulnerability profile concentrates in endpoint and systems-management products spanning desktop administration, backup, and intrusion prevention, with observed weakness classes centered on memory-buffer boundary violations and code-injection flaws. These are characteristic of native-code management and security agents that operate with elevated privileges and parse untrusted input from heterogeneous endpoints. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Computer Associates over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1472HIGH Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11 | Mar 24, 2008 | 9.3 | 70 | NO | YES |
CVE-2008-1328HIGH Buffer overflow in the LGServer service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary co | Apr 7, 2008 | 9.3 | 34 | NO | NO |
CVE-2008-1329HIGH Unspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute a | Apr 7, 2008 | 10.0 | 27 | NO | NO |
CVE-2008-1786HIGH The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Sui | Apr 16, 2008 | 9.3 | 25 | NO | NO |
CVE-2008-3174MEDIUM Unspecified vulnerability in the kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, allows remote | Aug 12, 2008 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Computer Associates.
Media articles that mention a CVE ID that affects a product developed by Computer Associates — matched by CVE ID, not by vendor name.