Symantec Veritas maintains a focused portfolio of enterprise backup, recovery, and cluster-management products such as Backup Exec, NetBackup, and Cluster Server that protect critical infrastructure and data across on-premises and hybrid environments. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability, reflecting the high-value target these data-protection platforms represent to attackers seeking to disrupt recovery operations or exfiltrate protected data. Recurring weakness patterns center on improper input validation in management interfaces and configuration systems, a structural risk inherent to complex administrative applications. Defenders should prioritize patches for internet-facing backup and recovery instances and audit administrative access paths; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Symantec Veritas over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2611HIGH VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static p | Aug 17, 2005 | 10.0 | 87 | NO | YES |
CVE-2004-1172HIGH Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitr | Jan 10, 2005 | 10.0 | 87 | NO | YES |
CVE-2005-0773HIGH Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary | Jun 18, 2005 | 7.5 | 81 | NO | YES |
CVE-2005-2715HIGH Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/ | Oct 12, 2005 | 10.0 | 70 | NO | YES |
CVE-2005-0771HIGH VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP | Jun 23, 2005 | 10.0 | 67 | NO | YES |
CVE-2005-3116HIGH Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote at | Nov 18, 2005 | 10.0 | 50 | NO | YES |
CVE-2002-1374HIGH The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, w | Dec 23, 2002 | 7.5 | 45 | NO | YES |
CVE-2002-1375HIGH The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. | Dec 23, 2002 | 7.5 | 42 | NO | YES |
CVE-2000-0494HIGH Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server scrip | Jun 16, 2000 | 7.2 | 29 | NO | YES |
CVE-2002-1376HIGH libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routi | Dec 23, 2002 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Symantec Veritas.
Media articles that mention a CVE ID that affects a product developed by Symantec Veritas — matched by CVE ID, not by vendor name.