peter bassill · operator
$ cve CVE-2006-6917 JSON

CVE-2006-6917 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 29.5% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS29.54% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
broadcombrightstor arcserve backup server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD