← Vulnerability feed

Vulnerability record · CVE-2011-2667 · published 28 July 2011

CVE-2011-2667: Broadcom total defense memory buffer overflow vulnerability

Broadcom · Total Defense

Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.

10.0 CVSS 2.0 High EPSS 16% · top 3.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2667 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-1653CA Total Defense UNC Server SQL injection via stored proceduresThe Unified Network Control (UNC) Server in CA Total Defense r12 before SE2 contains multiple SQL injection flaws in stored procedures such as UnAssi…EPSS 89%analysed10.0CVE-2011-0758Ca etrust secure content manager vulnerabilityThe eCS component (ECSQdmn.exe) in CA ETrust Secure Content Manager 8.0 and CA Gateway Security 8.1 allows remote attackers to cause a denial of serv…EPSS 8.2%9.3CVE-2009-3587Broadcom anti-virus vulnerabilityUnspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 throug…EPSS 7.6%7.5CVE-2011-1654Broadcom total defense path traversal vulnerabilityDirectory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r1…EPSS 11%7.5CVE-2011-1655Broadcom total defense vulnerabilityThe management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a …EPSS 12%4.3CVE-2009-3588Broadcom anti-virus vulnerabilityUnspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 throug…EPSS 2.4%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2011-2667), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.