Tolis Group maintains a backup and archiving software product line centered on BRU, which serves a specialized but persistent niche in enterprise data protection and recovery workflows. The durable signal in its disclosures centers on the product's data-handling and system-integration scope, with observed weakness patterns reflecting input-validation and parsing complexity common to backup software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tolis Group over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0584HIGH Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string speci | Aug 18, 2003 | 7.2 | 27 | NO | YES |
CVE-2002-0210HIGH setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file. | May 16, 2002 | 7.2 | 27 | NO | YES |
CVE-2000-0537HIGH BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable. | Jun 5, 2000 | 7.2 | 27 | NO | YES |
CVE-2002-1512MEDIUM xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file. | Apr 2, 2003 | 6.2 | 25 | NO | YES |
CVE-2003-0583HIGH Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument. | Aug 18, 2003 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tolis Group.
Media articles that mention a CVE ID that affects a product developed by Tolis Group — matched by CVE ID, not by vendor name.