hp CVE Vulnerabilities & Metrics

Focus on hp vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About hp Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hp. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hp CVEs: 1015
Earliest CVE date: 31 Dec 1990, 05:00 UTC
Latest CVE date: 18 Oct 2024, 16:15 UTC

Latest CVE reference: CVE-2024-42508

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 12

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -87.63%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -87.63%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hp CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.46

Max CVSS: 10.0

Critical CVEs (≥9): 635

CVSS Range vs. Count

Range Count
0.0-3.9 280
4.0-6.9 787
7.0-8.9 459
9.0-10.0 635

CVSS Distribution Chart

Top 5 Highest CVSS hp CVEs

These are the five CVEs with the highest CVSS scores for hp, sorted by severity first and recency.

All CVEs for hp

CVE-2024-42508 hp vulnerability CVSS: 0 18 Oct 2024, 16:15 UTC

This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

CVE-2024-7720 hp vulnerability CVSS: 0 27 Aug 2024, 18:15 UTC

HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.

CVE-2024-42400 hp vulnerability CVSS: 0 06 Aug 2024, 20:15 UTC

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVE-2024-42399 hp vulnerability CVSS: 0 06 Aug 2024, 20:15 UTC

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVE-2024-42398 hp vulnerability CVSS: 0 06 Aug 2024, 20:15 UTC

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVE-2024-42397 hp vulnerability CVSS: 0 06 Aug 2024, 19:15 UTC

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVE-2024-42396 hp vulnerability CVSS: 0 06 Aug 2024, 19:15 UTC

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

CVE-2024-42395 hp vulnerability CVSS: 0 06 Aug 2024, 19:15 UTC

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-42394 hp vulnerability CVSS: 0 06 Aug 2024, 19:15 UTC

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-42393 hp vulnerability CVSS: 0 06 Aug 2024, 19:15 UTC

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-22442 hp vulnerability CVSS: 0 16 Jul 2024, 16:15 UTC

The vulnerability could be remotely exploited to bypass authentication.

CVE-2024-6147 hp vulnerability CVSS: 0 20 Jun 2024, 20:15 UTC

Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271.

CVE-2023-6573 hp vulnerability CVSS: 0 23 Jan 2024, 18:15 UTC

HPE OneView may have a missing passphrase during restore.

CVE-2023-50275 hp vulnerability CVSS: 0 23 Jan 2024, 17:15 UTC

HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

CVE-2023-50274 hp vulnerability CVSS: 0 23 Jan 2024, 17:15 UTC

HPE OneView may allow command injection with local privilege escalation.

CVE-2023-50271 hp vulnerability CVSS: 0 17 Dec 2023, 15:15 UTC

A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.

CVE-2023-45627 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45626 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.

CVE-2023-45625 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2023-45624 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45623 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45622 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45621 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45620 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

CVE-2023-45619 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

CVE-2023-45618 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

CVE-2023-45617 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.

CVE-2023-45616 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-45615 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-45614 hp vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-5739 hp vulnerability CVSS: 0 31 Oct 2023, 16:15 UTC

Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.

CVE-2023-5671 hp vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.

CVE-2023-26300 hp vulnerability CVSS: 0 18 Oct 2023, 19:15 UTC

A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.

CVE-2023-5449 hp vulnerability CVSS: 0 13 Oct 2023, 17:15 UTC

A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature which may allow a monitor’s Theft Deterrence to be deactivated.

CVE-2023-5409 hp vulnerability CVSS: 0 13 Oct 2023, 17:15 UTC

HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to the potential vulnerability.

CVE-2023-4499 hp vulnerability CVSS: 0 13 Oct 2023, 17:15 UTC

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

CVE-2023-5365 hp vulnerability CVSS: 0 09 Oct 2023, 16:15 UTC

HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

CVE-2023-5113 hp vulnerability CVSS: 0 04 Oct 2023, 15:15 UTC

Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.

CVE-2023-30909 hp vulnerability CVSS: 0 14 Sep 2023, 15:15 UTC

A remote authentication bypass issue exists in some OneView APIs.

CVE-2023-30908 hp vulnerability CVSS: 0 07 Sep 2023, 22:15 UTC

A remote authentication bypass issue exists in a OneView API.

CVE-2015-2202 hp vulnerability CVSS: 0 05 Sep 2023, 18:15 UTC

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

CVE-2015-2201 hp vulnerability CVSS: 0 05 Sep 2023, 18:15 UTC

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

CVE-2015-1391 hp vulnerability CVSS: 0 05 Sep 2023, 18:15 UTC

Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.

CVE-2015-1390 hp vulnerability CVSS: 0 05 Sep 2023, 18:15 UTC

Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

CVE-2022-4894 hp vulnerability CVSS: 0 16 Aug 2023, 21:15 UTC

Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element.

CVE-2023-38402 hp vulnerability CVSS: 0 15 Aug 2023, 19:15 UTC

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process.

CVE-2023-38401 hp vulnerability CVSS: 0 15 Aug 2023, 19:15 UTC

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system.

CVE-2023-35982 hp vulnerability CVSS: 0 25 Jul 2023, 19:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-35981 hp vulnerability CVSS: 0 25 Jul 2023, 19:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-35980 hp vulnerability CVSS: 0 25 Jul 2023, 19:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-26301 hp vulnerability CVSS: 0 21 Jul 2023, 17:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.

CVE-2023-35178 hp vulnerability CVSS: 0 30 Jun 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.

CVE-2023-35177 hp vulnerability CVSS: 0 30 Jun 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.

CVE-2023-35176 hp vulnerability CVSS: 0 30 Jun 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.

CVE-2023-35175 hp vulnerability CVSS: 0 30 Jun 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

CVE-2023-26299 hp vulnerability CVSS: 0 30 Jun 2023, 16:15 UTC

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

CVE-2023-30903 hp vulnerability CVSS: 0 16 Jun 2023, 21:15 UTC

HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.

CVE-2023-1329 hp vulnerability CVSS: 0 14 Jun 2023, 21:15 UTC

A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.

CVE-2022-31646 hp vulnerability CVSS: 0 14 Jun 2023, 18:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31645 hp vulnerability CVSS: 0 14 Jun 2023, 18:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31644 hp vulnerability CVSS: 0 14 Jun 2023, 18:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31642 hp vulnerability CVSS: 0 14 Jun 2023, 17:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31641 hp vulnerability CVSS: 0 14 Jun 2023, 17:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31640 hp vulnerability CVSS: 0 14 Jun 2023, 17:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2023-1707 hp vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.

CVE-2022-31639 hp vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31638 hp vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31637 hp vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31636 hp vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2022-31635 hp vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVE-2023-32674 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.

CVE-2023-32673 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.

CVE-2023-26298 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

CVE-2023-26297 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

CVE-2023-26296 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

CVE-2023-26295 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

CVE-2023-26294 hp vulnerability CVSS: 0 12 Jun 2023, 22:15 UTC

Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

CVE-2022-43778 hp vulnerability CVSS: 0 12 Jun 2023, 20:15 UTC

Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

CVE-2022-43777 hp vulnerability CVSS: 0 12 Jun 2023, 20:15 UTC

Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

CVE-2022-27541 hp vulnerability CVSS: 0 12 Jun 2023, 19:15 UTC

Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

CVE-2022-27539 hp vulnerability CVSS: 0 12 Jun 2023, 19:15 UTC

Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

CVE-2019-16283 hp vulnerability CVSS: 0 09 Jun 2023, 18:15 UTC

A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.

CVE-2023-22791 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker.

CVE-2023-22790 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2023-22789 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2023-22788 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2023-22787 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

CVE-2023-22786 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22785 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22784 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22783 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22782 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22781 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22780 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-22779 hp vulnerability CVSS: 0 08 May 2023, 15:15 UTC

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2023-28092 hp vulnerability CVSS: 0 01 May 2023, 15:15 UTC

A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could result in the system being vulnerable to exploits by attackers with physical access inside the server chassis.

CVE-2023-27973 hp vulnerability CVSS: 0 28 Apr 2023, 17:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

CVE-2023-1526 hp vulnerability CVSS: 0 28 Apr 2023, 17:15 UTC

Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.

CVE-2023-27972 hp vulnerability CVSS: 0 28 Apr 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

CVE-2023-27971 hp vulnerability CVSS: 0 28 Apr 2023, 16:15 UTC

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

CVE-2022-31643 hp vulnerability CVSS: 0 28 Apr 2023, 16:15 UTC

A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.

CVE-2023-28084 hp vulnerability CVSS: 0 25 Apr 2023, 20:15 UTC

HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

CVE-2023-28090 hp vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

An HPE OneView appliance dump may expose SNMPv3 read credentials

CVE-2023-28089 hp vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

CVE-2023-28088 hp vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

An HPE OneView appliance dump may expose SAN switch administrative credentials

CVE-2023-28087 hp vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

An HPE OneView appliance dump may expose OneView user accounts

CVE-2023-28086 hp vulnerability CVSS: 0 25 Apr 2023, 19:15 UTC

An HPE OneView appliance dump may expose proxy credential settings

CVE-2023-28091 hp vulnerability CVSS: 0 14 Apr 2023, 15:15 UTC

HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump

CVE-2023-28083 hp vulnerability CVSS: 0 22 Mar 2023, 06:15 UTC

A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

CVE-2022-37935 hp vulnerability CVSS: 0 01 Mar 2023, 08:15 UTC

HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.

CVE-2022-43779 hp vulnerability CVSS: 0 12 Feb 2023, 04:15 UTC

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.

CVE-2022-48311 hp vulnerability CVSS: 0 06 Feb 2023, 21:15 UTC

**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2022-3990 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for automatic updates should have already received the remediation.

CVE-2022-27538 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.

CVE-2022-27537 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.

CVE-2022-23455 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

CVE-2022-23454 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

CVE-2022-23453 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

CVE-2021-3809 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.

CVE-2021-3808 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.

CVE-2021-3439 hp vulnerability CVSS: 0 01 Feb 2023, 07:15 UTC

HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.

CVE-2022-37934 hp vulnerability CVSS: 0 05 Jan 2023, 07:15 UTC

A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotely exploited to allow remote directory traversal in HPE OfficeConnect 1820 switch series version PT.02.17 and below, HPE OfficeConnect 1850 switch series version PC.01.23 and below, and HPE OfficeConnect 1850 (10G aggregator) switch version PO.01.22 and below.

CVE-2022-38395 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.

CVE-2022-37018 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

CVE-2022-2794 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

CVE-2022-1038 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.

CVE-2021-46846 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

CVE-2021-3942 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.

CVE-2021-3919 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability.

CVE-2021-3661 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

CVE-2021-3437 hp vulnerability CVSS: 0 12 Dec 2022, 13:15 UTC

Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities.

CVE-2022-37931 hp vulnerability CVSS: 0 22 Nov 2022, 05:15 UTC

A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

CVE-2022-28722 hp vulnerability CVSS: 0 26 Sep 2022, 15:15 UTC

Certain HP Print Products are potentially vulnerable to Buffer Overflow.

CVE-2022-28721 hp vulnerability CVSS: 0 26 Sep 2022, 15:15 UTC

Certain HP Print Products are potentially vulnerable to Remote Code Execution.

CVE-2022-1602 hp vulnerability CVSS: 0 13 Sep 2022, 15:15 UTC

A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the potential vulnerability introduced in SP8.

CVE-2022-23678 hp vulnerability CVSS: 0 06 Sep 2022, 18:15 UTC

A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system versions: 4.3.0 build 2208101 and below. Aruba has released upgrades for Virtual Intranet Access (VIA) Client that address this security vulnerability.

CVE-2022-28625 hp vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be configured with credential access to external repositories. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-28616 hp vulnerability CVSS: 7.5 17 May 2022, 21:15 UTC

A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-28617 hp vulnerability CVSS: 7.5 17 May 2022, 20:15 UTC

A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-23706 hp vulnerability CVSS: 4.3 17 May 2022, 20:15 UTC

A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-23704 hp vulnerability CVSS: 5.0 09 May 2022, 21:15 UTC

A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later.

CVE-2022-27239 hp vulnerability CVSS: 7.2 27 Apr 2022, 14:15 UTC

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

CVE-2022-23700 hp vulnerability CVSS: 2.1 04 Apr 2022, 20:15 UTC

A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-23699 hp vulnerability CVSS: 4.6 04 Apr 2022, 20:15 UTC

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-23698 hp vulnerability CVSS: 5.0 04 Apr 2022, 20:15 UTC

A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-23697 hp vulnerability CVSS: 4.3 04 Apr 2022, 20:15 UTC

A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVE-2022-24293 hp vulnerability CVSS: 10.0 23 Mar 2022, 20:15 UTC

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

CVE-2022-24292 hp vulnerability CVSS: 10.0 23 Mar 2022, 20:15 UTC

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

CVE-2022-24291 hp vulnerability CVSS: 7.8 23 Mar 2022, 20:15 UTC

Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

CVE-2022-23958 hp vulnerability CVSS: 2.1 02 Mar 2022, 22:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2022-23957 hp vulnerability CVSS: 2.1 02 Mar 2022, 22:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2022-23955 hp vulnerability CVSS: 2.1 02 Mar 2022, 22:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2022-23954 hp vulnerability CVSS: 2.1 02 Mar 2022, 22:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2022-23956 hp vulnerability CVSS: 4.9 02 Mar 2022, 21:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2022-23953 hp vulnerability CVSS: 4.9 02 Mar 2022, 21:15 UTC

Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

CVE-2021-29220 hp vulnerability CVSS: 9.0 24 Feb 2022, 22:15 UTC

Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and availability. HPE has provided a software update to resolve this vulnerability in HPE iLO Amplifier Pack.

CVE-2021-39301 hp vulnerability CVSS: 7.2 16 Feb 2022, 17:15 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVE-2021-39300 hp vulnerability CVSS: 7.2 16 Feb 2022, 17:15 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVE-2021-39299 hp vulnerability CVSS: 7.2 16 Feb 2022, 17:15 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVE-2021-39298 hp vulnerability CVSS: 7.2 16 Feb 2022, 17:15 UTC

A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

CVE-2021-39297 hp vulnerability CVSS: 7.2 16 Feb 2022, 17:15 UTC

Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

CVE-2020-6922 hp vulnerability CVSS: 6.8 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6921 hp vulnerability CVSS: 6.8 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6920 hp vulnerability CVSS: 4.3 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6919 hp vulnerability CVSS: 6.8 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6918 hp vulnerability CVSS: 6.8 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6917 hp vulnerability CVSS: 6.8 16 Feb 2022, 17:15 UTC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2022-23456 hp vulnerability CVSS: 2.1 28 Jan 2022, 20:15 UTC

Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.

CVE-2021-3965 hp vulnerability CVSS: 5.0 14 Jan 2022, 20:15 UTC

Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

CVE-2021-29214 hp vulnerability CVSS: 6.5 10 Dec 2021, 17:15 UTC

A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this vulnerability. This vulnerability impacts SSMC versions 3.4 GA to 3.8.1.

CVE-2020-28419 hp vulnerability CVSS: 6.8 09 Nov 2021, 19:15 UTC

During installation with certain driver software or application packages an arbitrary code execution could occur.

CVE-2019-18914 hp vulnerability CVSS: 4.3 09 Nov 2021, 15:15 UTC

A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.

CVE-2019-18912 hp vulnerability CVSS: 4.6 09 Nov 2021, 15:15 UTC

A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

CVE-2019-16240 hp vulnerability CVSS: 5.8 09 Nov 2021, 15:15 UTC

A Buffer Overflow and Information Disclosure issue exists in HP OfficeJet Pro Printers before 001.1937C, and HP PageWide Managed Printers and HP PageWide Pro Printers before 001.1937D exists; A maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

CVE-2020-6931 hp vulnerability CVSS: 4.6 03 Nov 2021, 20:15 UTC

HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.

CVE-2020-28416 hp vulnerability CVSS: 4.6 03 Nov 2021, 20:15 UTC

HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

CVE-2021-39238 hp vulnerability CVSS: 7.5 03 Nov 2021, 01:15 UTC

Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overflow.

CVE-2021-39237 hp vulnerability CVSS: 2.1 03 Nov 2021, 01:15 UTC

Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure.

CVE-2021-3440 hp vulnerability CVSS: 4.6 01 Nov 2021, 14:15 UTC

HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevation of privilege.

CVE-2021-29212 hp vulnerability CVSS: 10.0 01 Nov 2021, 14:15 UTC

A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arbitrary code leading complete impact to confidentiality, integrity, and availability of the iLO Amplifier Pack appliance.

CVE-2021-3662 hp vulnerability CVSS: 3.5 29 Oct 2021, 12:15 UTC

Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).

CVE-2021-3441 hp vulnerability CVSS: 3.5 29 Oct 2021, 12:15 UTC

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

CVE-2021-26586 hp vulnerability CVSS: 5.0 05 Aug 2021, 21:15 UTC

A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM).

CVE-2021-26584 hp vulnerability CVSS: 4.3 03 Jun 2021, 11:15 UTC

A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

CVE-2021-3438 hp vulnerability CVSS: 4.6 20 May 2021, 14:15 UTC

A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

CVE-2021-26583 hp vulnerability CVSS: 7.5 10 May 2021, 13:15 UTC

A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.

CVE-2021-29203 hp vulnerability CVSS: 10.0 06 May 2021, 21:15 UTC

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

CVE-2021-26582 hp vulnerability CVSS: 4.3 15 Apr 2021, 18:15 UTC

A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).

CVE-2021-25140 hp vulnerability CVSS: 10.0 09 Feb 2021, 17:15 UTC

A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a directory traversal in user supplied input to the `khuploadfile.cgi` CGI ELF. The directory traversal could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.

CVE-2021-25139 hp vulnerability CVSS: 10.0 09 Feb 2021, 17:15 UTC

A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a stack based buffer overflow using user supplied input to the `khuploadfile.cgi` CGI ELF. The stack based buffer overflow could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.

CVE-2020-7203 hp vulnerability CVSS: 7.5 18 Dec 2020, 23:15 UTC

A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.

CVE-2020-7200 hp vulnerability CVSS: 7.5 18 Dec 2020, 23:15 UTC

A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.

CVE-2020-7199 hp vulnerability CVSS: 10.0 02 Dec 2020, 01:15 UTC

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.

CVE-2020-7198 hp vulnerability CVSS: 6.5 06 Nov 2020, 15:15 UTC

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

CVE-2020-7207 hp vulnerability CVSS: 7.2 05 Nov 2020, 21:15 UTC

A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.

CVE-2020-7197 hp vulnerability CVSS: 7.5 26 Oct 2020, 16:15 UTC

SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.

CVE-2020-7196 hp vulnerability CVSS: 4.0 26 Oct 2020, 16:15 UTC

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

CVE-2020-11853 hp vulnerability CVSS: 6.5 22 Oct 2020, 21:15 UTC

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

CVE-2020-7195 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7194 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7193 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7192 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7191 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A devsoftsel expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7190 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A deviceselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7189 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A faultflasheventselectfact expression language injectionremote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7188 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A userselectpagingcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7187 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A reportpage index expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7186 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A powershellconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7185 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A tvxlanlegend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7184 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A viewbatchtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7183 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A forwardredirect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7182 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A sshconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7181 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A smsrulesdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7180 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A ictexpertdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7179 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A thirdpartyperfselecttask expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7178 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7177 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A wmiconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7176 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A viewtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7175 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A iccselectdymicparam expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7174 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A soapconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7173 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A actionselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7172 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7171 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7170 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7169 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7168 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7167 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7166 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A operatorgrouptreeselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7165 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7164 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A operationselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7163 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A navigationto expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7162 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7161 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7160 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A iccselectdeviceseries expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7159 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A customtemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7158 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A perfselecttask expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7157 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A selviewnavcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7156 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A faultinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7155 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7154 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A ifviewselectpage expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7153 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7152 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A faultparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7151 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7150 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A faultstatchoosefaulttype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7149 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7148 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A deployselectsoftware expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7147 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7146 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A devgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7145 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7144 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7143 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7142 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-7141 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24652 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24651 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24650 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24649 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24648 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24647 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24646 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24630 hp vulnerability CVSS: 9.0 19 Oct 2020, 18:15 UTC

A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-24629 hp vulnerability CVSS: 10.0 19 Oct 2020, 18:15 UTC

A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

CVE-2020-15596 hp vulnerability CVSS: 4.6 12 Aug 2020, 22:15 UTC

The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

CVE-2019-18619 hp vulnerability CVSS: 4.6 22 Jul 2020, 14:15 UTC

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

CVE-2019-18618 hp vulnerability CVSS: 3.6 22 Jul 2020, 14:15 UTC

Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.

CVE-2020-7206 hp vulnerability CVSS: 7.5 17 Jul 2020, 22:15 UTC

HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.

CVE-2019-12000 hp vulnerability CVSS: 5.4 17 Jul 2020, 22:15 UTC

HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.

CVE-2020-7140 hp vulnerability CVSS: 4.3 08 Jul 2020, 14:15 UTC

A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess

CVE-2020-12695 hp vulnerability CVSS: 7.8 08 Jun 2020, 17:15 UTC

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVE-2020-7135 hp vulnerability CVSS: 4.6 27 Apr 2020, 15:15 UTC

A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux. The vulnerable software is included in the HPE Service Pack for ProLiant (SPP) releases 2018.06.0, 2018.09.0, and 2018.11.0. The vulnerable software is the Supplemental Update / Online ROM Flash Component for Linux (x64) software. The installer in this software component could be locally exploited to execute arbitrary code. Drive Models can be found in the Vulnerability Resolution field of the security bulletin. The 2019_03 SPP and Supplemental update / Online ROM Flash Component for Linux (x64) after 2019.03.0 has fixed this issue.

CVE-2020-7134 hp vulnerability CVSS: 4.0 24 Apr 2020, 19:15 UTC

A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

CVE-2020-7133 hp vulnerability CVSS: 7.5 24 Apr 2020, 19:15 UTC

A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

CVE-2020-7131 hp vulnerability CVSS: 9.0 24 Apr 2020, 18:15 UTC

This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintenance Entity products. All J/H-series NonStop systems have a security vulnerability associated with an open UDP port 17185 on the Maintenance LAN which could result in information disclosure, denial-of-service attacks or local memory corruption against the affected system and a complete control of the system may also be possible. This vulnerability exists only if one gains access to the Maintenance LAN to which Blade Maintenance Entity, Integrated Maintenance Entity or Maintenance Entity product is connected. **Workaround:** Block the UDP port 17185(In the Maintenance LAN Network Switch/Firewall). Fix: Install following SPRs, which are already available: * T1805A01^AAI (Integrated Maintenance Entity) * T4805A01^AAZ (Blade Maintenance Entity). These SPRs are also usable with the following RVUs: * J06.19.00 ? J06.23.01. No fix planned for the following RVUs: J06.04.00 ? J06.18.01. No fix planned for H-Series NonStop systems. No fix planned for the product T2805 (Maintenance Entity).

CVE-2020-7132 hp vulnerability CVSS: 3.5 23 Apr 2020, 18:15 UTC

A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE Onboard Administrator. * OA 4.95 (Linux and Windows).

CVE-2019-18917 hp vulnerability CVSS: 6.4 16 Mar 2020, 20:15 UTC

A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.

CVE-2017-10992 hp vulnerability CVSS: 10.0 10 Mar 2020, 13:15 UTC

In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.

CVE-2020-7130 hp vulnerability CVSS: 5.0 04 Mar 2020, 21:15 UTC

HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.

CVE-2012-6277 hp vulnerability CVSS: 9.3 21 Feb 2020, 17:15 UTC

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."

CVE-2020-7209 hp vulnerability CVSS: 7.5 13 Feb 2020, 00:15 UTC

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

CVE-2020-7208 hp vulnerability CVSS: 4.3 13 Feb 2020, 00:15 UTC

LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.

CVE-2019-18915 hp vulnerability CVSS: 7.2 13 Feb 2020, 00:15 UTC

A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.

CVE-2012-1994 hp vulnerability CVSS: 2.7 10 Feb 2020, 16:15 UTC

HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information

CVE-2015-2802 hp vulnerability CVSS: 5.0 04 Feb 2020, 21:15 UTC

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.

CVE-2019-18567 hp vulnerability CVSS: 3.3 03 Feb 2020, 18:15 UTC

Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.

CVE-2019-18913 hp vulnerability CVSS: 7.2 31 Jan 2020, 04:15 UTC

A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs that support Microsoft Windows 10 Kernel DMA protection. Affected versions depend on platform (prior to 01.04.02; or prior to 02.04.01; or prior to 02.04.02).

CVE-2015-0949 hp vulnerability CVSS: 4.6 30 Jan 2020, 21:15 UTC

The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to bypass the Secure Boot protection mechanism and gain privileges by leveraging write access to physical memory.

CVE-2019-19539 hp vulnerability CVSS: 2.1 27 Jan 2020, 19:15 UTC

An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.

CVE-2014-7303 hp vulnerability CVSS: 7.2 27 Jan 2020, 18:15 UTC

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.

CVE-2014-7302 hp vulnerability CVSS: 7.2 27 Jan 2020, 18:15 UTC

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.

CVE-2014-7301 hp vulnerability CVSS: 4.6 27 Jan 2020, 18:15 UTC

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.

CVE-2019-3683 hp vulnerability CVSS: 6.5 17 Jan 2020, 11:15 UTC

The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.

CVE-2019-11997 hp vulnerability CVSS: 4.3 16 Jan 2020, 19:15 UTC

A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the vulnerability in eIUM. The eIUM 8.3 FP01 customers are advised to install eIUM83FP01Patch_QXCR1001711284.20190806-1244 patch. The eIUM 9.0 customers are advised to upgrade to eIUM 9.0 FP02 PI5 or later versions. For other versions, please, contact the product support.

CVE-2019-6319 hp vulnerability CVSS: 5.8 09 Jan 2020, 20:15 UTC

HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

CVE-2019-6332 hp vulnerability CVSS: 3.5 09 Jan 2020, 19:15 UTC

A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink Advantage 2600 All-in-One Printer series model numbers V1N02A - V1N02B, Y5Z00A - Y5Z04B; HP DeskJet Ink Advantage 5000 All-in-One Printer series model numbers M2U86A - M2U89B; HP DeskJet Ink Advantage 5200 All-in-One Printer series model numbers M2U76A - M2U78B; HP ENVY 5000 All-in-One Printer series model numbers M2U85A - M2U85B, M2U91A - M2U94B, Z4A54A - Z4A74A; HP ENVY Photo 6200 All-in-One Printer series model numbers K7G18A-K7G26B, K7S21B, Y0K13D - Y0K15A; HP ENVY Photo 7100 All-in-One Printer series model numbers 3XD89A, K7G93A-K7G99A, Z3M37A - Z3M52A; HP ENVY Photo 7800 All-in-One Printer series model numbers K7R96A, K7S00A - K7S10D, Y0G42D - Y0G52B; HP Ink Tank Wireless 410 series model numbers Z4B53A - Z4B55A, Z6Z95A - Z6Z99A, 4DX94A - 4DX95A, 4YF79A, Z7A01A; HP OfficeJet 5200 All-in-One Printer series model numbers M2U75A, M2U81A-M2U84B, Z4B12A - Z4B14A, Z4B27A - Z4B29A; HP Smart Tank Wireless 450 series model numbers Z4B56A, Z6Z96A - Z6Z98A.

CVE-2019-6320 hp vulnerability CVSS: 5.8 09 Jan 2020, 19:15 UTC

Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

CVE-2019-11994 hp vulnerability CVSS: 7.5 03 Jan 2020, 18:15 UTC

A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command manifest file during upgrade does not correctly prevent directory traversal and so can be used to execute manifest files in arbitrary locations on the node. The API does not require user authentication and is accessible over the management network, resulting in the potential for unauthenticated remote execution of manifest files. For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061901&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

CVE-2019-11993 hp vulnerability CVSS: 9.4 03 Jan 2020, 18:15 UTC

A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. Two now deprecated APIs run as root, accept a file name path, and can be used to create or delete arbitrary files on the nodes. These APIs do not require user authentication and are accessible over the management network, resulting in remote availability and integrity vulnerabilities For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061675&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

CVE-2019-11995 hp vulnerability CVSS: 5.0 18 Dec 2019, 20:15 UTC

Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.

CVE-2019-11992 hp vulnerability CVSS: 4.3 18 Dec 2019, 16:15 UTC

A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.

CVE-2019-18910 hp vulnerability CVSS: 4.6 22 Nov 2019, 22:15 UTC

The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

CVE-2019-18909 hp vulnerability CVSS: 7.7 22 Nov 2019, 22:15 UTC

The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.

CVE-2019-16287 hp vulnerability CVSS: 7.2 22 Nov 2019, 22:15 UTC

In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker to executed commands with elevated privileges.

CVE-2019-16286 hp vulnerability CVSS: 4.6 22 Nov 2019, 22:15 UTC

An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.

CVE-2019-16285 hp vulnerability CVSS: 2.1 22 Nov 2019, 22:15 UTC

If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.

CVE-2019-10627 hp vulnerability CVSS: 7.5 21 Nov 2019, 15:15 UTC

Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2

CVE-2019-11135 hp vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVE-2019-6337 hp vulnerability CVSS: 3.3 07 Nov 2019, 15:15 UTC

For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

CVE-2019-16284 hp vulnerability CVSS: 9.0 05 Nov 2019, 21:15 UTC

A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.

CVE-2019-6334 hp vulnerability CVSS: 7.5 16 Oct 2019, 15:15 UTC

HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.

CVE-2019-6335 hp vulnerability CVSS: 5.0 11 Oct 2019, 18:15 UTC

A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially be exploited to create a denial of service.

CVE-2019-6333 hp vulnerability CVSS: 7.2 11 Oct 2019, 17:15 UTC

A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system service.

CVE-2019-11656 hp vulnerability CVSS: 3.5 04 Oct 2019, 20:15 UTC

Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

CVE-2019-11655 hp vulnerability CVSS: 6.5 04 Oct 2019, 20:15 UTC

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVE-2019-5408 hp vulnerability CVSS: 6.4 09 Aug 2019, 18:15 UTC

Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.

CVE-2019-5407 hp vulnerability CVSS: 6.5 09 Aug 2019, 18:15 UTC

A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5406 hp vulnerability CVSS: 9.0 09 Aug 2019, 18:15 UTC

A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5405 hp vulnerability CVSS: 5.0 09 Aug 2019, 18:15 UTC

A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5404 hp vulnerability CVSS: 8.7 09 Aug 2019, 18:15 UTC

A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5403 hp vulnerability CVSS: 3.5 09 Aug 2019, 18:15 UTC

A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5402 hp vulnerability CVSS: 10.0 09 Aug 2019, 18:15 UTC

A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

CVE-2019-5400 hp vulnerability CVSS: 6.5 09 Aug 2019, 18:15 UTC

A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5399 hp vulnerability CVSS: 9.7 09 Aug 2019, 18:15 UTC

A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5398 hp vulnerability CVSS: 3.5 09 Aug 2019, 18:15 UTC

A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5397 hp vulnerability CVSS: 9.7 09 Aug 2019, 18:15 UTC

A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5396 hp vulnerability CVSS: 9.7 09 Aug 2019, 17:15 UTC

A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5395 hp vulnerability CVSS: 6.5 09 Aug 2019, 17:15 UTC

A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CVE-2019-5401 hp vulnerability CVSS: 3.5 01 Aug 2019, 22:15 UTC

A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.

CVE-2019-3486 hp vulnerability CVSS: 4.3 25 Jul 2019, 15:15 UTC

Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1

CVE-2019-3485 hp vulnerability CVSS: 4.3 24 Jul 2019, 16:15 UTC

Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1

CVE-2019-2842 hp vulnerability CVSS: 4.3 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JCE). The supported version that is affected is Java SE: 8u212. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2019-2816 hp vulnerability CVSS: 5.8 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).

CVE-2019-2786 hp vulnerability CVSS: 2.6 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).

CVE-2019-2769 hp vulnerability CVSS: 5.0 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2019-2766 hp vulnerability CVSS: 2.6 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

CVE-2019-2762 hp vulnerability CVSS: 5.0 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2019-2745 hp vulnerability CVSS: 1.9 23 Jul 2019, 23:15 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-11990 hp vulnerability CVSS: 9.0 19 Jul 2019, 22:15 UTC

Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603 * For customers with release UIoT 1.5, fixes are made available with 1.5 RP503 HF3 * For customers with release older than 1.5, such as 1.4.0, 1.4.1, 1.4.2 and 1.2.4.2, the resolution will be to upgrade to 1.5 RP503 HF3 or 1.6 RP603 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.

CVE-2019-11989 hp vulnerability CVSS: 7.1 19 Jul 2019, 22:15 UTC

A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.

CVE-2019-11991 hp vulnerability CVSS: 9.7 09 Jul 2019, 19:15 UTC

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

CVE-2019-6329 hp vulnerability CVSS: 7.2 25 Jun 2019, 17:15 UTC

HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.

CVE-2019-6328 hp vulnerability CVSS: 7.2 25 Jun 2019, 17:15 UTC

HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.

CVE-2019-6327 hp vulnerability CVSS: 7.5 17 Jun 2019, 16:15 UTC

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an IPP Parser potentially vulnerable to Buffer Overflow.

CVE-2019-5394 hp vulnerability CVSS: 4.9 05 Jun 2019, 18:29 UTC

The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

CVE-2019-11983 hp vulnerability CVSS: 8.3 05 Jun 2019, 17:29 UTC

A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

CVE-2019-11982 hp vulnerability CVSS: 7.6 05 Jun 2019, 17:29 UTC

A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

CVE-2019-11986 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11985 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11984 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11980 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11979 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11978 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11977 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11976 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11975 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11974 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11973 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11972 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11971 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11970 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11969 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11968 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11967 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11966 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote privilege escalation vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11965 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11964 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11963 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11962 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11961 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11960 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11959 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11958 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11957 hp vulnerability CVSS: 9.3 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11956 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11955 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11954 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11953 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11952 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11951 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11950 hp vulnerability CVSS: 9.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11949 hp vulnerability CVSS: 10.0 05 Jun 2019, 16:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5393 hp vulnerability CVSS: 6.8 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5392 hp vulnerability CVSS: 5.0 05 Jun 2019, 15:29 UTC

A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5391 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A stack buffer overflow vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5390 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5389 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5388 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5387 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5386 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5385 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5384 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5383 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5382 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5381 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5380 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5379 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5378 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5377 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5376 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5375 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5374 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5373 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5372 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5371 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5370 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5369 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5368 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5367 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5366 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5365 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5364 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5363 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5362 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5361 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5360 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5359 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5358 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5357 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5356 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5355 hp vulnerability CVSS: 7.8 05 Jun 2019, 15:29 UTC

A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5354 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5353 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5352 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5351 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5350 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5349 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5348 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5347 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5346 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5345 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5344 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5343 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5342 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5341 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5340 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5339 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5338 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11948 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11947 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11946 hp vulnerability CVSS: 6.8 05 Jun 2019, 15:29 UTC

A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11945 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11944 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11943 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11942 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11941 hp vulnerability CVSS: 9.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-7125 hp vulnerability CVSS: 6.5 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-7124 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-7123 hp vulnerability CVSS: 7.8 05 Jun 2019, 15:29 UTC

A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-7122 hp vulnerability CVSS: 5.0 05 Jun 2019, 15:29 UTC

A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-7121 hp vulnerability CVSS: 10.0 05 Jun 2019, 15:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-6322 hp vulnerability CVSS: 9.0 29 May 2019, 20:29 UTC

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default.

CVE-2019-6321 hp vulnerability CVSS: 9.0 29 May 2019, 20:29 UTC

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default.

CVE-2018-7120 hp vulnerability CVSS: 7.5 10 May 2019, 19:29 UTC

A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.50, which is part of the HPE Synergy Custom SPP 2018.11.20190205, could allow local or remote unauthorized elevation of privilege.

CVE-2018-7119 hp vulnerability CVSS: 1.9 10 May 2019, 19:29 UTC

A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions before T6533L01^ADU or T6533H05^ADW, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND and all versions on H-series . Note that some commands in NonStop Safeguard and NonStop Standard Security software require username and password to be passed as command line parameters, which may lead to a local disclosure of the credentials.

CVE-2019-2698 hp vulnerability CVSS: 6.8 23 Apr 2019, 19:32 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2019-2697 hp vulnerability CVSS: 6.8 23 Apr 2019, 19:32 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2019-2684 hp vulnerability CVSS: 4.3 23 Apr 2019, 19:32 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2019-2602 hp vulnerability CVSS: 5.0 23 Apr 2019, 19:32 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2019-6318 hp vulnerability CVSS: 7.5 11 Apr 2019, 15:29 UTC

HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.

CVE-2018-7118 hp vulnerability CVSS: 4.6 09 Apr 2019, 19:29 UTC

A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software earlier than version 2018.09.0.

CVE-2018-7117 hp vulnerability CVSS: 4.3 09 Apr 2019, 19:29 UTC

A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.

CVE-2017-2752 hp vulnerability CVSS: 2.1 27 Mar 2019, 17:29 UTC

A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to customer data as a result of this issue.

CVE-2017-2748 hp vulnerability CVSS: 5.0 27 Mar 2019, 17:29 UTC

A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue.

CVE-2018-5927 hp vulnerability CVSS: 4.1 27 Mar 2019, 16:29 UTC

HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.

CVE-2018-5926 hp vulnerability CVSS: 6.4 27 Mar 2019, 16:29 UTC

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVE-2018-5923 hp vulnerability CVSS: 7.5 27 Mar 2019, 16:29 UTC

In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.

CVE-2019-3484 hp vulnerability CVSS: 7.2 25 Mar 2019, 17:29 UTC

Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.

CVE-2019-3483 hp vulnerability CVSS: 6.8 25 Mar 2019, 17:29 UTC

Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

CVE-2019-3482 hp vulnerability CVSS: 6.8 25 Mar 2019, 17:29 UTC

Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

CVE-2019-3481 hp vulnerability CVSS: 7.5 25 Mar 2019, 17:29 UTC

Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

CVE-2019-3480 hp vulnerability CVSS: 4.3 25 Mar 2019, 17:29 UTC

Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.

CVE-2019-3479 hp vulnerability CVSS: 7.5 25 Mar 2019, 17:29 UTC

Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.

CVE-2018-15532 hp vulnerability CVSS: 2.1 21 Mar 2019, 16:00 UTC

SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.

CVE-2019-5736 hp vulnerability CVSS: 9.3 11 Feb 2019, 19:29 UTC

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

CVE-2019-7317 hp vulnerability CVSS: 2.6 04 Feb 2019, 08:29 UTC

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

CVE-2018-5740 hp vulnerability CVSS: 5.0 16 Jan 2019, 20:29 UTC

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVE-2019-2426 hp vulnerability CVSS: 4.3 16 Jan 2019, 19:30 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-2422 hp vulnerability CVSS: 2.6 16 Jan 2019, 19:30 UTC

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

CVE-2018-18593 hp vulnerability CVSS: 5.0 31 Dec 2018, 15:29 UTC

Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information

CVE-2018-7116 hp vulnerability CVSS: 5.0 03 Dec 2018, 15:29 UTC

HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via dbman Opcode 10003 'Filename'. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

CVE-2018-7115 hp vulnerability CVSS: 5.0 03 Dec 2018, 15:29 UTC

HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

CVE-2018-7114 hp vulnerability CVSS: 10.0 03 Dec 2018, 15:29 UTC

HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbman leading to code execution. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

CVE-2018-7113 hp vulnerability CVSS: 7.2 03 Dec 2018, 15:29 UTC

A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates.

CVE-2018-7112 hp vulnerability CVSS: 4.9 03 Dec 2018, 15:29 UTC

The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the original Spectre/Meltdown set of vulnerabilities. At that time, the Windows firmware installer was also updated in the versions of HPE Integrated Lights-Out 2, 3, and 4 (iLO 2, 3, and 4) listed in the security bulletin. The updated HPE Windows firmware installer was released in the system ROM and HPE Integrated Lights-Out (iLO) releases documented in earlier HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.

CVE-2018-7111 hp vulnerability CVSS: 5.0 17 Oct 2018, 13:29 UTC

A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by other users.

CVE-2018-7076 hp vulnerability CVSS: 10.0 17 Oct 2018, 13:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.

CVE-2018-3214 hp vulnerability CVSS: 5.0 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-3183 hp vulnerability CVSS: 6.8 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected are Java SE: 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVE-2018-3180 hp vulnerability CVSS: 6.8 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVE-2018-3169 hp vulnerability CVSS: 5.1 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g. code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2018-3149 hp vulnerability CVSS: 5.1 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2018-3139 hp vulnerability CVSS: 2.6 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g. code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

CVE-2018-3136 hp vulnerability CVSS: 2.6 17 Oct 2018, 01:31 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g. code installed by an administrator). CVSS 3.0 Base Score 3.4 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N).

CVE-2018-5921 hp vulnerability CVSS: 6.8 03 Oct 2018, 20:29 UTC

A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.

CVE-2017-2751 hp vulnerability CVSS: 2.1 03 Oct 2018, 20:29 UTC

A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

CVE-2018-9069 hp vulnerability CVSS: 7.0 02 Oct 2018, 13:29 UTC

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

CVE-2018-7109 hp vulnerability CVSS: 5.5 27 Sep 2018, 18:29 UTC

HPE has addressed a remote arbitrary file modification vulnerability in HPE enhanced Internet Usage Manager (eIUM) v9.0FP1 with the cumulative patch for v9.0FP1 - eIUM90FP01XXX.YYYYMMDD-HHMM.

CVE-2018-7105 hp vulnerability CVSS: 9.0 27 Sep 2018, 18:29 UTC

A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to disclosure of information.

CVE-2018-7104 hp vulnerability CVSS: 10.0 27 Sep 2018, 18:29 UTC

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

CVE-2018-7103 hp vulnerability CVSS: 10.0 27 Sep 2018, 18:29 UTC

A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

CVE-2018-7102 hp vulnerability CVSS: 5.0 27 Sep 2018, 18:29 UTC

A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remotely exploited via directory traversal to allow remote arbitrary file modification.

CVE-2018-7101 hp vulnerability CVSS: 5.0 27 Sep 2018, 18:29 UTC

A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30.

CVE-2018-6505 hp vulnerability CVSS: 5.0 20 Sep 2018, 19:29 UTC

A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Unauthenticated File Downloads.

CVE-2018-6503 hp vulnerability CVSS: 6.8 20 Sep 2018, 19:29 UTC

A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for vulnerable Access Controls.

CVE-2018-6502 hp vulnerability CVSS: 4.3 20 Sep 2018, 19:29 UTC

A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Reflected Cross-site Scripting (XSS).

CVE-2018-6501 hp vulnerability CVSS: 4.0 20 Sep 2018, 16:29 UTC

Potential security vulnerability of Insufficient Access Controls has been identified in ArcSight Management Center (ArcMC) for versions prior to 2.81. This vulnerability could be exploited to allow for insufficient access controls.

CVE-2018-6500 hp vulnerability CVSS: 5.0 20 Sep 2018, 16:29 UTC

A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be remotely exploited to allow Directory Traversal.

CVE-2018-7099 hp vulnerability CVSS: 2.1 14 Aug 2018, 14:29 UTC

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.

CVE-2018-7098 hp vulnerability CVSS: 3.6 14 Aug 2018, 14:29 UTC

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.

CVE-2018-7097 hp vulnerability CVSS: 6.8 14 Aug 2018, 14:29 UTC

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow cross-site request forgery.

CVE-2018-7096 hp vulnerability CVSS: 7.5 14 Aug 2018, 14:29 UTC

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow code execution.

CVE-2018-7095 hp vulnerability CVSS: 7.5 14 Aug 2018, 14:29 UTC

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow access restriction bypass.

CVE-2018-7093 hp vulnerability CVSS: 7.8 14 Aug 2018, 14:29 UTC

A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.

CVE-2018-5925 hp vulnerability CVSS: 9.3 13 Aug 2018, 15:29 UTC

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.

CVE-2018-5924 hp vulnerability CVSS: 7.5 13 Aug 2018, 15:29 UTC

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.

CVE-2018-7092 hp vulnerability CVSS: 6.4 06 Aug 2018, 20:29 UTC

A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09. The vulnerability could be remotely exploited to allow for remote directory traversal leading to arbitrary file deletion.

CVE-2018-7091 hp vulnerability CVSS: 5.8 06 Aug 2018, 20:29 UTC

HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.

CVE-2018-7090 hp vulnerability CVSS: 4.3 06 Aug 2018, 20:29 UTC

HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.

CVE-2018-7078 hp vulnerability CVSS: 9.0 06 Aug 2018, 20:29 UTC

A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

CVE-2018-7075 hp vulnerability CVSS: 4.3 06 Aug 2018, 20:29 UTC

A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version.

CVE-2018-7074 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resolved in iMC PLAT 7.3 E0605P04 or subsequent version.

CVE-2018-7073 hp vulnerability CVSS: 2.1 06 Aug 2018, 20:29 UTC

A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

CVE-2018-7072 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

CVE-2018-7071 hp vulnerability CVSS: 4.0 06 Aug 2018, 20:29 UTC

HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.

CVE-2018-5390 hp vulnerability CVSS: 7.8 06 Aug 2018, 20:29 UTC

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.

CVE-2017-9000 hp vulnerability CVSS: 5.0 06 Aug 2018, 20:29 UTC

ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file access. An unauthenticated user with network access to an Aruba mobility controller on TCP port 8080 or 8081 may be able to access arbitrary files stored on the mobility controller. Ports 8080 and 8081 are used for captive portal functionality and are listening, by default, on all IP interfaces of the mobility controller, including captive portal interfaces. The attacker could access files which could contain passwords, keys, and other sensitive information that could lead to full system compromise.

CVE-2017-8990 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version.

CVE-2017-8989 hp vulnerability CVSS: 6.4 06 Aug 2018, 20:29 UTC

A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.

CVE-2017-8988 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A Remote Bypass of Security Restrictions vulnerability was identified in HPE XP Command View Advanced Edition Software Earlier than 8.5.3-00. The vulnerability impacts DevMgr Earlier than 8.5.3-00 (for Windows, Linux), RepMgr earlier than 8.5.3-00 (for Windows, Linux) and HDLM earlier than 8.5.3-00 (for Windows, Linux, Solaris, AIX).

CVE-2017-8987 hp vulnerability CVSS: 7.8 06 Aug 2018, 20:29 UTC

A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.

CVE-2017-8968 hp vulnerability CVSS: 7.2 06 Aug 2018, 20:29 UTC

A remote execution of arbitrary code vulnerability has been identified in HPE RESTful Interface Tool 1.5, 2.0 (hprest-1.5-79.x86_64.rpm, ilorest-2.0-403.x86_64.rpm). The issue is resolved in iLOREST v2.1 or subsequent versions.

CVE-2016-8527 hp vulnerability CVSS: 4.3 06 Aug 2018, 20:29 UTC

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into AirWave in the same browser.

CVE-2016-8526 hp vulnerability CVSS: 4.0 06 Aug 2018, 20:29 UTC

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

CVE-2016-4406 hp vulnerability CVSS: 4.3 06 Aug 2018, 20:29 UTC

A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.

CVE-2016-4405 hp vulnerability CVSS: 6.5 06 Aug 2018, 20:29 UTC

A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26

CVE-2016-4404 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via a memory allocation issue.

CVE-2016-4403 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via memory corruption.

CVE-2016-4402 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via buffer overflow.

CVE-2016-4400 hp vulnerability CVSS: 3.5 06 Aug 2018, 20:29 UTC

A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).

CVE-2016-4399 hp vulnerability CVSS: 3.5 06 Aug 2018, 20:29 UTC

A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).

CVE-2016-4398 hp vulnerability CVSS: 6.5 06 Aug 2018, 20:29 UTC

A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.

CVE-2016-4397 hp vulnerability CVSS: 4.6 06 Aug 2018, 20:29 UTC

A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.

CVE-2016-4392 hp vulnerability CVSS: 3.5 06 Aug 2018, 20:29 UTC

A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.

CVE-2016-4391 hp vulnerability CVSS: 7.5 06 Aug 2018, 20:29 UTC

A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.

CVE-2016-9597 hp vulnerability CVSS: 5.0 30 Jul 2018, 14:29 UTC

It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.

CVE-2017-12151 hp vulnerability CVSS: 5.8 27 Jul 2018, 12:29 UTC

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.

CVE-2017-3210 hp vulnerability CVSS: 7.2 24 Jul 2018, 15:29 UTC

Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges. The following applications have been identified by Portrait Displays as affected: Fujitsu DisplayView Click: Version 6.0 and 6.01. The issue was fixed in Version 6.3. Fujitsu DisplayView Click Suite: Version 5. The issue is addressed by patch in Version 5.9. HP Display Assistant: Version 2.1. The issue was fixed in Version 2.11. HP My Display: Version 2.0. The issue was fixed in Version 2.1. Philips Smart Control Premium: Versions 2.23, 2.25. The issue was fixed in Version 2.26.

CVE-2018-2973 hp vulnerability CVSS: 4.3 18 Jul 2018, 13:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2018-2952 hp vulnerability CVSS: 4.3 18 Jul 2018, 13:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2940 hp vulnerability CVSS: 4.3 18 Jul 2018, 13:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).

CVE-2018-12463 hp vulnerability CVSS: 7.5 12 Jul 2018, 16:29 UTC

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVE-2017-7658 hp vulnerability CVSS: 7.5 26 Jun 2018, 17:29 UTC

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

CVE-2017-7657 hp vulnerability CVSS: 7.5 26 Jun 2018, 16:29 UTC

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

CVE-2018-6493 hp vulnerability CVSS: 6.5 22 May 2018, 19:29 UTC

SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.

CVE-2018-6492 hp vulnerability CVSS: 4.3 22 May 2018, 19:29 UTC

Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.

CVE-2018-2815 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2814 hp vulnerability CVSS: 5.1 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2018-2800 hp vulnerability CVSS: 4.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, JRockit accessible data as well as unauthorized read access to a subset of Java SE, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).

CVE-2018-2799 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2798 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2797 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2796 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2795 hp vulnerability CVSS: 5.0 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2794 hp vulnerability CVSS: 3.7 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, JRockit executes to compromise Java SE, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2018-2790 hp vulnerability CVSS: 2.6 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).

CVE-2018-2783 hp vulnerability CVSS: 5.8 19 Apr 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u161 and 8u152; Java SE Embedded: 8u152; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, JRockit accessible data as well as unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVE-2018-6490 hp vulnerability CVSS: 7.8 02 Mar 2018, 01:29 UTC

Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.

CVE-2017-8985 hp vulnerability CVSS: 4.6 15 Feb 2018, 22:29 UTC

HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability in HGLM version HGLM 6.3.0-00 to 8.5.2-00.

CVE-2017-8984 hp vulnerability CVSS: 9.3 15 Feb 2018, 22:29 UTC

A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.

CVE-2017-8983 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

CVE-2017-8982 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

CVE-2017-8981 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.

CVE-2017-8980 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8979 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.

CVE-2017-8978 hp vulnerability CVSS: 4.9 15 Feb 2018, 22:29 UTC

A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.

CVE-2017-8977 hp vulnerability CVSS: 8.5 15 Feb 2018, 22:29 UTC

A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

CVE-2017-8976 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

CVE-2017-8975 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

CVE-2017-8974 hp vulnerability CVSS: 3.6 15 Feb 2018, 22:29 UTC

A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found.

CVE-2017-8973 hp vulnerability CVSS: 4.0 15 Feb 2018, 22:29 UTC

An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVE-2017-8972 hp vulnerability CVSS: 4.0 15 Feb 2018, 22:29 UTC

A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVE-2017-8971 hp vulnerability CVSS: 4.0 15 Feb 2018, 22:29 UTC

A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVE-2017-8970 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVE-2017-8969 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CVE-2017-8967 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8966 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8965 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8964 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8963 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8962 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-8961 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.

CVE-2017-8960 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found.

CVE-2017-8959 hp vulnerability CVSS: 6.5 15 Feb 2018, 22:29 UTC

An Authentication Bypass vulnerability in HPE MSA 1040 and HPE MSA 2040 SAN Storage in version GL220P008 and earlier and was found.

CVE-2017-8958 hp vulnerability CVSS: 9.3 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found.

CVE-2017-8957 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-8956 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-8955 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-8954 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-8953 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.

CVE-2017-8952 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

CVE-2017-8951 hp vulnerability CVSS: 4.6 15 Feb 2018, 22:29 UTC

A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

CVE-2017-8950 hp vulnerability CVSS: 2.1 15 Feb 2018, 22:29 UTC

A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

CVE-2017-8949 hp vulnerability CVSS: 2.1 15 Feb 2018, 22:29 UTC

A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

CVE-2017-8948 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Bypass Security Restriction vulnerability in HPE Network Node Manager i (NNMi) Software versions v10.0x, v10.1x, v10.2x was found.

CVE-2017-8947 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.

CVE-2017-8946 hp vulnerability CVSS: 7.6 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.

CVE-2017-8945 hp vulnerability CVSS: 5.8 15 Feb 2018, 22:29 UTC

A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.

CVE-2017-5823 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5822 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5821 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5820 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5819 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5818 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5817 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5816 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5815 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

CVE-2017-5814 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVE-2017-5813 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVE-2017-5812 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVE-2017-5811 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVE-2017-5810 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVE-2017-5809 hp vulnerability CVSS: 4.9 15 Feb 2018, 22:29 UTC

A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

CVE-2017-5808 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

CVE-2017-5807 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

CVE-2017-5806 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-5805 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-5804 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

CVE-2017-5803 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found.

CVE-2017-5802 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.

CVE-2017-5801 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.

CVE-2017-5800 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found.

CVE-2017-5799 hp vulnerability CVSS: 6.5 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

CVE-2017-5798 hp vulnerability CVSS: 4.3 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

CVE-2017-5797 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A Remote Unauthenticated Disclosure of Information vulnerability in HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501) was found.

CVE-2017-5795 hp vulnerability CVSS: 7.1 15 Feb 2018, 22:29 UTC

A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was found.

CVE-2017-5794 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

CVE-2017-5793 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Arbitrary Code Execution vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

CVE-2017-5792 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

CVE-2017-5790 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

CVE-2017-5788 hp vulnerability CVSS: 4.9 15 Feb 2018, 22:29 UTC

A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.

CVE-2017-5787 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.

CVE-2017-5786 hp vulnerability CVSS: 2.1 15 Feb 2018, 22:29 UTC

A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14

CVE-2017-5785 hp vulnerability CVSS: 6.4 15 Feb 2018, 22:29 UTC

A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-5784 hp vulnerability CVSS: 5.8 15 Feb 2018, 22:29 UTC

A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-5783 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-5782 hp vulnerability CVSS: 5.8 15 Feb 2018, 22:29 UTC

A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-5781 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-5780 hp vulnerability CVSS: 4.3 15 Feb 2018, 22:29 UTC

A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVE-2017-12561 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.

CVE-2017-12560 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.

CVE-2017-12559 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.

CVE-2017-12558 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

CVE-2017-12557 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

CVE-2017-12556 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

CVE-2017-12555 hp vulnerability CVSS: 6.8 15 Feb 2018, 22:29 UTC

A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.

CVE-2017-12554 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT iMC Plat 7.3 E0504P2 and earlier was found.

CVE-2017-12553 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12552 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12551 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12550 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12549 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12548 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12547 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12546 hp vulnerability CVSS: 5.5 15 Feb 2018, 22:29 UTC

A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12545 hp vulnerability CVSS: 7.8 15 Feb 2018, 22:29 UTC

A remote denial of service vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12544 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12543 hp vulnerability CVSS: 4.0 15 Feb 2018, 22:29 UTC

A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

CVE-2017-12542 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

CVE-2017-12541 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12540 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12539 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12538 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12537 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12536 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12535 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12534 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12533 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12532 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12531 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12530 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12529 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12528 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12527 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12526 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12525 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12524 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12523 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12522 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12521 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12520 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12519 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12518 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12517 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12516 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12515 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12514 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12513 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12512 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12511 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12510 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12509 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12508 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12507 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12506 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12505 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12504 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12503 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12502 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12501 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12500 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12499 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12498 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12497 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12496 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12495 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12494 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12493 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12492 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12491 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12490 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12489 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12488 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2017-12487 hp vulnerability CVSS: 9.0 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVE-2016-8535 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.

CVE-2016-8534 hp vulnerability CVSS: 6.5 15 Feb 2018, 22:29 UTC

A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

CVE-2016-8533 hp vulnerability CVSS: 6.5 15 Feb 2018, 22:29 UTC

A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

CVE-2016-8532 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.

CVE-2016-8531 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found.

CVE-2016-8530 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.

CVE-2016-8529 hp vulnerability CVSS: 7.3 15 Feb 2018, 22:29 UTC

A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.

CVE-2016-8525 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A Remote Disclosure of Information vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.

CVE-2016-8522 hp vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVE-2016-8521 hp vulnerability CVSS: 4.3 15 Feb 2018, 22:29 UTC

A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVE-2016-8519 hp vulnerability CVSS: 10.0 15 Feb 2018, 22:29 UTC

A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.

CVE-2016-8518 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote denial of service vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

CVE-2016-8517 hp vulnerability CVSS: 4.3 15 Feb 2018, 22:29 UTC

A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

CVE-2016-8516 hp vulnerability CVSS: 5.0 15 Feb 2018, 22:29 UTC

A remote denial of service vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

CVE-2016-8515 hp vulnerability CVSS: 6.5 15 Feb 2018, 22:29 UTC

A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

CVE-2016-8514 hp vulnerability CVSS: 4.0 15 Feb 2018, 22:29 UTC

A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

CVE-2016-8513 hp vulnerability CVSS: 6.0 15 Feb 2018, 22:29 UTC

A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

CVE-2016-8512 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.

CVE-2016-8511 hp vulnerability CVSS: 7.5 15 Feb 2018, 22:29 UTC

A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.

CVE-2017-17482 hp vulnerability CVSS: 4.6 07 Feb 2018, 15:29 UTC

An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.

CVE-2017-2750 hp vulnerability CVSS: 7.5 23 Jan 2018, 16:29 UTC

Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise printers before 2308937_578479, 2405087_018548, and other firmware versions.

CVE-2017-2747 hp vulnerability CVSS: 2.1 23 Jan 2018, 16:29 UTC

HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

CVE-2017-2746 hp vulnerability CVSS: 4.3 23 Jan 2018, 16:29 UTC

Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to create a denial of service.

CVE-2017-2745 hp vulnerability CVSS: 4.3 23 Jan 2018, 16:29 UTC

Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to execute scripts in a user's browser.

CVE-2017-2744 hp vulnerability CVSS: 2.1 23 Jan 2018, 16:29 UTC

The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.

CVE-2017-2743 hp vulnerability CVSS: 4.3 23 Jan 2018, 16:29 UTC

HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be exploited to perform a cross site scripting (XSS) attack.

CVE-2017-2742 hp vulnerability CVSS: 7.8 23 Jan 2018, 16:29 UTC

A potential security vulnerability has been identified with HP Web Jetadmin before 10.4 SR2. This vulnerability could potentially be exploited to create a denial of service.

CVE-2017-2741 hp vulnerability CVSS: 10.0 23 Jan 2018, 16:29 UTC

A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.

CVE-2017-2740 hp vulnerability CVSS: 7.2 23 Jan 2018, 16:29 UTC

A potential security vulnerability has been identified with the command line shell of the HP ThinPro operating system 6.1, 5.2.1, 5.2, 5.1, 5.0, and 4.4. The vulnerability could result in a local unauthorized elevation of privilege on an HP thin client device.

CVE-2018-2678 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).

CVE-2018-2677 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).

CVE-2018-2663 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).

CVE-2018-2657 hp vulnerability CVSS: 5.0 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2641 hp vulnerability CVSS: 2.6 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 6.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N).

CVE-2018-2637 hp vulnerability CVSS: 5.8 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, JRockit accessible data as well as unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVE-2018-2634 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).

CVE-2018-2633 hp vulnerability CVSS: 5.1 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVE-2018-2629 hp vulnerability CVSS: 2.6 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N).

CVE-2018-2618 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2018-2603 hp vulnerability CVSS: 5.0 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-2602 hp vulnerability CVSS: 3.7 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded executes to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as unauthorized read access to a subset of Java SE, Java SE Embedded accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).

CVE-2018-2599 hp vulnerability CVSS: 5.8 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).

CVE-2018-2588 hp vulnerability CVSS: 4.0 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2018-2582 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).

CVE-2018-2579 hp vulnerability CVSS: 4.3 18 Jan 2018, 02:29 UTC

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2017-5641 hp vulnerability CVSS: 7.5 28 Dec 2017, 15:29 UTC

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One vector in the Java standard library exists that allows an attacker to trigger possibly further exploitable Java deserialization of untrusted data. Other known vectors in third party libraries can be used to trigger remote code execution.

CVE-2017-17556 hp vulnerability CVSS: 3.6 15 Dec 2017, 19:29 UTC

A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.

CVE-2017-14360 hp vulnerability CVSS: 5.0 08 Nov 2017, 14:29 UTC

A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).

CVE-2017-14359 hp vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.

CVE-2017-14358 hp vulnerability CVSS: 5.8 31 Oct 2017, 15:29 UTC

A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.

CVE-2017-14357 hp vulnerability CVSS: 4.3 31 Oct 2017, 15:29 UTC

A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)

CVE-2017-14356 hp vulnerability CVSS: 7.5 31 Oct 2017, 15:29 UTC

An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.

CVE-2017-5791 hp vulnerability CVSS: 10.0 11 Oct 2017, 21:29 UTC

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

CVE-2017-5789 hp vulnerability CVSS: 7.5 11 Oct 2017, 21:29 UTC

HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow.

CVE-2017-8994 hp vulnerability CVSS: 7.5 10 Oct 2017, 21:29 UTC

A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.

CVE-2017-14354 hp vulnerability CVSS: 4.3 05 Oct 2017, 15:29 UTC

A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting.

CVE-2017-14353 hp vulnerability CVSS: 6.8 05 Oct 2017, 15:29 UTC

A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution.

CVE-2017-14352 hp vulnerability CVSS: 4.3 30 Sep 2017, 01:29 UTC

A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow cross-site scripting.

CVE-2017-14351 hp vulnerability CVSS: 7.5 30 Sep 2017, 01:29 UTC

A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution.

CVE-2017-14350 hp vulnerability CVSS: 10.0 30 Sep 2017, 01:29 UTC

A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution.

CVE-2017-14349 hp vulnerability CVSS: 7.5 30 Sep 2017, 01:29 UTC

An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data.

CVE-2017-13991 hp vulnerability CVSS: 5.0 30 Sep 2017, 01:29 UTC

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.

CVE-2017-13990 hp vulnerability CVSS: 5.0 30 Sep 2017, 01:29 UTC

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.

CVE-2017-13989 hp vulnerability CVSS: 5.5 30 Sep 2017, 01:29 UTC

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.

CVE-2017-13988 hp vulnerability CVSS: 4.0 30 Sep 2017, 01:29 UTC

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.

CVE-2017-13987 hp vulnerability CVSS: 4.0 30 Sep 2017, 01:29 UTC

An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.

CVE-2017-13986 hp vulnerability CVSS: 4.3 30 Sep 2017, 01:29 UTC

A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.

CVE-2017-13985 hp vulnerability CVSS: 4.0 30 Sep 2017, 01:29 UTC

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.

CVE-2017-13984 hp vulnerability CVSS: 5.5 30 Sep 2017, 01:29 UTC

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.

CVE-2017-13983 hp vulnerability CVSS: 10.0 30 Sep 2017, 01:29 UTC

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication.

CVE-2017-13982 hp vulnerability CVSS: 9.0 30 Sep 2017, 01:29 UTC

A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.

CVE-2015-0839 hp vulnerability CVSS: 6.8 02 Aug 2017, 19:29 UTC

The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.

CVE-2016-4383 hp vulnerability CVSS: 8.5 27 Jun 2017, 20:29 UTC

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

CVE-2015-5436 hp vulnerability CVSS: 7.8 11 May 2017, 14:29 UTC

A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and later, but prior to version 2.30. The vulnerability could be exploited remotely resulting in Denial of Service (DoS). Note this was originally published in 2015 however the CVE entry was added in 2020.

CVE-2017-3733 hp vulnerability CVSS: 5.0 04 May 2017, 19:29 UTC

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVE-2017-5638 hp vulnerability CVSS: 10.0 11 Mar 2017, 02:59 UTC

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CVE-2016-8106 hp vulnerability CVSS: 4.3 09 Jan 2017, 21:59 UTC

A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.

CVE-2016-2246 hp vulnerability CVSS: 7.2 29 Dec 2016, 09:59 UTC

HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended access restrictions and gain privileges via unspecified vectors.

CVE-2016-4396 hp vulnerability CVSS: 7.8 28 Oct 2016, 21:59 UTC

HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

CVE-2016-4395 hp vulnerability CVSS: 7.8 28 Oct 2016, 21:59 UTC

HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

CVE-2016-4394 hp vulnerability CVSS: 5.8 28 Oct 2016, 21:59 UTC

HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.

CVE-2016-4393 hp vulnerability CVSS: 3.5 28 Oct 2016, 21:59 UTC

HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

CVE-2016-4390 hp vulnerability CVSS: 6.8 05 Oct 2016, 10:59 UTC

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4388, and CVE-2016-4389.

CVE-2016-4389 hp vulnerability CVSS: 6.8 05 Oct 2016, 10:59 UTC

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4388, and CVE-2016-4390.

CVE-2016-4388 hp vulnerability CVSS: 6.8 05 Oct 2016, 10:59 UTC

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4389, and CVE-2016-4390.

CVE-2016-4387 hp vulnerability CVSS: 6.8 05 Oct 2016, 10:59 UTC

The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4388, CVE-2016-4389, and CVE-2016-4390.

CVE-2016-4386 hp vulnerability CVSS: 6.9 29 Sep 2016, 14:59 UTC

HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.

CVE-2016-4385 hp vulnerability CVSS: 7.5 29 Sep 2016, 14:59 UTC

The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.

CVE-2016-2776 hp vulnerability CVSS: 7.8 28 Sep 2016, 10:59 UTC

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

CVE-2016-6306 hp vulnerability CVSS: 4.3 26 Sep 2016, 19:59 UTC

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

CVE-2016-4384 hp vulnerability CVSS: 9.0 21 Sep 2016, 02:59 UTC

HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.

CVE-2016-4382 hp vulnerability CVSS: 6.0 21 Sep 2016, 02:59 UTC

HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user validation failure" issue.

CVE-2016-2182 hp vulnerability CVSS: 7.5 16 Sep 2016, 05:59 UTC

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.

CVE-2016-4381 hp vulnerability CVSS: 4.4 08 Sep 2016, 16:59 UTC

HPE XP7 Command View Advanced Edition (CVAE) Suite 6.x through 8.x before 8.4.1-02, when Replication Manager (RepMgr) and Device Manager (DevMgr) are enabled, allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2016-4380 hp vulnerability CVSS: 3.5 08 Sep 2016, 16:59 UTC

Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4379 hp vulnerability CVSS: 4.3 08 Sep 2016, 16:59 UTC

The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.

CVE-2016-4375 hp vulnerability CVSS: 7.5 08 Sep 2016, 16:59 UTC

Multiple unspecified vulnerabilities in HPE Integrated Lights-Out 3 (aka iLO 3) firmware before 1.88, Integrated Lights-Out 4 (aka iLO 4) firmware before 2.44, and Integrated Lights-Out 4 (aka iLO 4) mRCA firmware before 2.32 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2016-4378 hp vulnerability CVSS: 5.0 26 Aug 2016, 19:59 UTC

The (1) Device Manager, (2) Tiered Storage Manager, (3) Replication Manager, (4) Replication Monitor, and (5) Hitachi Automation Director (HAD) components in HPE XP P9000 Command View Advanced Edition Software before 8.4.1-00 and XP7 Command View Advanced Edition Suite before 8.4.1-00 allow remote attackers to obtain sensitive information via unspecified vectors.

CVE-2016-4377 hp vulnerability CVSS: 7.6 22 Aug 2016, 10:59 UTC

HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before 16.11.1, Sizer for ConvergedSystems Virtualization before 16.7.1, Sizer for Microsoft Exchange Server before 16.12.1, Sizer for Microsoft Lync Server 2013 before 16.12.1, Sizer for Microsoft SharePoint 2013 before 16.13.1, Sizer for Microsoft SharePoint 2010 before 16.11.1, and Sizer for Microsoft Skype for Business Server 2015 before 16.5.1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2016-4374 hp vulnerability CVSS: 4.0 08 Aug 2016, 00:59 UTC

HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors.

CVE-2016-4373 hp vulnerability CVSS: 7.5 01 Aug 2016, 02:59 UTC

The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-2775 hp vulnerability CVSS: 4.3 19 Jul 2016, 22:59 UTC

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

CVE-2016-5388 hp vulnerability CVSS: 5.1 19 Jul 2016, 02:00 UTC

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

CVE-2016-5387 hp vulnerability CVSS: 6.8 19 Jul 2016, 02:00 UTC

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.

CVE-2016-5385 hp vulnerability CVSS: 5.1 19 Jul 2016, 02:00 UTC

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

CVE-2016-4372 hp vulnerability CVSS: 7.5 15 Jul 2016, 16:59 UTC

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-3092 hp vulnerability CVSS: 7.8 04 Jul 2016, 22:59 UTC

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVE-2016-2177 hp vulnerability CVSS: 7.5 20 Jun 2016, 01:59 UTC

OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.

CVE-2016-4371 hp vulnerability CVSS: 6.0 19 Jun 2016, 01:59 UTC

HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.

CVE-2016-4448 hp vulnerability CVSS: 10.0 09 Jun 2016, 16:59 UTC

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

CVE-2016-4447 hp vulnerability CVSS: 5.0 09 Jun 2016, 16:59 UTC

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

CVE-2016-4369 hp vulnerability CVSS: 6.5 08 Jun 2016, 15:00 UTC

HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2016-4368 hp vulnerability CVSS: 7.5 08 Jun 2016, 14:59 UTC

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-4367 hp vulnerability CVSS: 5.0 08 Jun 2016, 14:59 UTC

The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2016-4366 hp vulnerability CVSS: 7.5 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

CVE-2016-4365 hp vulnerability CVSS: 5.0 08 Jun 2016, 14:59 UTC

HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2016-4364 hp vulnerability CVSS: 7.2 08 Jun 2016, 14:59 UTC

HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.

CVE-2016-4363 hp vulnerability CVSS: 4.3 08 Jun 2016, 14:59 UTC

HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.

CVE-2016-4362 hp vulnerability CVSS: 5.5 08 Jun 2016, 14:59 UTC

HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVE-2016-4361 hp vulnerability CVSS: 5.0 08 Jun 2016, 14:59 UTC

HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow remote attackers to cause a denial of service via unspecified vectors.

CVE-2016-4360 hp vulnerability CVSS: 6.4 08 Jun 2016, 14:59 UTC

web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.

CVE-2016-4359 hp vulnerability CVSS: 7.5 08 Jun 2016, 14:59 UTC

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.

CVE-2016-4358 hp vulnerability CVSS: 4.8 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2029.

CVE-2016-4357 hp vulnerability CVSS: 7.5 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028.

CVE-2016-2030 hp vulnerability CVSS: 5.5 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2022.

CVE-2016-2029 hp vulnerability CVSS: 6.4 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358.

CVE-2016-2028 hp vulnerability CVSS: 5.5 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4357.

CVE-2016-2027 hp vulnerability CVSS: 5.0 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026.

CVE-2016-2026 hp vulnerability CVSS: 5.0 08 Jun 2016, 14:59 UTC

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027.

CVE-2016-2024 hp vulnerability CVSS: 7.5 08 Jun 2016, 14:59 UTC

HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

CVE-2016-2022 hp vulnerability CVSS: 4.7 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2030.

CVE-2016-2021 hp vulnerability CVSS: 7.7 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2022, and CVE-2016-2030.

CVE-2016-2020 hp vulnerability CVSS: 8.5 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

CVE-2016-2019 hp vulnerability CVSS: 7.7 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

CVE-2016-2018 hp vulnerability CVSS: 6.4 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

CVE-2016-2017 hp vulnerability CVSS: 5.5 08 Jun 2016, 14:59 UTC

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

CVE-2016-2025 hp vulnerability CVSS: 5.0 30 May 2016, 01:59 UTC

HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components.

CVE-2016-2023 hp vulnerability CVSS: 2.1 30 May 2016, 01:59 UTC

HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.

CVE-2016-1999 hp vulnerability CVSS: 10.0 30 May 2016, 01:59 UTC

The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2016-4543 hp vulnerability CVSS: 7.5 22 May 2016, 01:59 UTC

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

CVE-2016-3705 hp vulnerability CVSS: 5.0 17 May 2016, 14:08 UTC

The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.

CVE-2016-3627 hp vulnerability CVSS: 5.0 17 May 2016, 14:08 UTC

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.

CVE-2016-2016 hp vulnerability CVSS: 2.1 14 May 2016, 15:59 UTC

Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.

CVE-2016-2015 hp vulnerability CVSS: 6.6 14 May 2016, 15:59 UTC

HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

CVE-2016-3710 hp vulnerability CVSS: 7.2 11 May 2016, 21:59 UTC

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVE-2016-2014 hp vulnerability CVSS: 8.5 07 May 2016, 10:59 UTC

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVE-2016-2013 hp vulnerability CVSS: 4.0 07 May 2016, 10:59 UTC

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2016-2012 hp vulnerability CVSS: 7.5 07 May 2016, 10:59 UTC

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.

CVE-2016-2011 hp vulnerability CVSS: 3.5 07 May 2016, 10:59 UTC

Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.

CVE-2016-2010 hp vulnerability CVSS: 3.5 07 May 2016, 10:59 UTC

Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.

CVE-2016-2009 hp vulnerability CVSS: 6.5 07 May 2016, 10:59 UTC

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-2107 hp vulnerability CVSS: 2.6 05 May 2016, 01:59 UTC

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

CVE-2016-2008 hp vulnerability CVSS: 7.5 21 Apr 2016, 11:00 UTC

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2016-2007 hp vulnerability CVSS: 10.0 21 Apr 2016, 11:00 UTC

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3354.

CVE-2016-2006 hp vulnerability CVSS: 10.0 21 Apr 2016, 11:00 UTC

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3353.

CVE-2016-2005 hp vulnerability CVSS: 10.0 21 Apr 2016, 11:00 UTC

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.

CVE-2016-2004 hp vulnerability CVSS: 9.3 21 Apr 2016, 11:00 UTC

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.

CVE-2016-2003 hp vulnerability CVSS: 7.5 20 Apr 2016, 17:59 UTC

HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-2002 hp vulnerability CVSS: 10.0 20 Apr 2016, 17:59 UTC

The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.

CVE-2016-2001 hp vulnerability CVSS: 5.8 12 Apr 2016, 23:59 UTC

HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection attacks via unspecified vectors.

CVE-2016-2000 hp vulnerability CVSS: 7.5 05 Apr 2016, 18:59 UTC

HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVE-2016-1998 hp vulnerability CVSS: 10.0 22 Mar 2016, 10:59 UTC

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2016-1997 hp vulnerability CVSS: 10.0 22 Mar 2016, 10:59 UTC

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2016-2245 hp vulnerability CVSS: 10.0 19 Mar 2016, 15:59 UTC

HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.

CVE-2016-1996 hp vulnerability CVSS: 3.6 18 Mar 2016, 10:59 UTC

HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.

CVE-2016-1995 hp vulnerability CVSS: 10.0 18 Mar 2016, 10:59 UTC

HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2016-1994 hp vulnerability CVSS: 4.0 18 Mar 2016, 10:59 UTC

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2016-1993 hp vulnerability CVSS: 5.5 18 Mar 2016, 10:59 UTC

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVE-2016-1992 hp vulnerability CVSS: 4.0 17 Mar 2016, 14:59 UTC

HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2016-1989 hp vulnerability CVSS: 10.0 15 Mar 2016, 00:59 UTC

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988.

CVE-2016-1988 hp vulnerability CVSS: 10.0 15 Mar 2016, 00:59 UTC

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.

CVE-2016-2244 hp vulnerability CVSS: 5.0 04 Mar 2016, 15:59 UTC

HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.

CVE-2016-2243 hp vulnerability CVSS: 5.4 04 Mar 2016, 15:59 UTC

Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.

CVE-2016-1987 hp vulnerability CVSS: 2.6 18 Feb 2016, 22:59 UTC

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

CVE-2015-7547 hp vulnerability CVSS: 6.8 18 Feb 2016, 21:59 UTC

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

CVE-2016-1986 hp vulnerability CVSS: 7.5 12 Feb 2016, 01:59 UTC

HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2016-0728 hp vulnerability CVSS: 7.2 08 Feb 2016, 03:59 UTC

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

CVE-2016-1985 hp vulnerability CVSS: 10.0 30 Jan 2016, 15:59 UTC

HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVE-2015-6864 hp vulnerability CVSS: 6.5 16 Jan 2016, 05:59 UTC

HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

CVE-2015-6863 hp vulnerability CVSS: 7.5 16 Jan 2016, 05:59 UTC

HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

CVE-2016-0778 hp vulnerability CVSS: 4.6 14 Jan 2016, 22:59 UTC

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.

CVE-2016-0777 hp vulnerability CVSS: 4.0 14 Jan 2016, 22:59 UTC

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

CVE-2015-6862 hp vulnerability CVSS: 7.2 08 Jan 2016, 02:59 UTC

HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

CVE-2015-6860 hp vulnerability CVSS: 7.2 05 Jan 2016, 11:59 UTC

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.

CVE-2015-6859 hp vulnerability CVSS: 4.6 05 Jan 2016, 11:59 UTC

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860.

CVE-2015-6858 hp vulnerability CVSS: 4.3 05 Jan 2016, 11:59 UTC

HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2015-5447 hp vulnerability CVSS: 3.5 05 Jan 2016, 11:59 UTC

Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-5446 hp vulnerability CVSS: 5.8 05 Jan 2016, 11:59 UTC

HP StoreOnce Backup system software before 3.13.1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-5445 hp vulnerability CVSS: 6.8 05 Jan 2016, 11:59 UTC

Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVE-2015-5434 hp vulnerability CVSS: 6.4 05 Jan 2016, 11:59 UTC

HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping."

CVE-2015-8651 hp vulnerability CVSS: 9.3 28 Dec 2015, 23:59 UTC

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2015-8317 hp vulnerability CVSS: 5.0 15 Dec 2015, 21:59 UTC

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

CVE-2015-8242 hp vulnerability CVSS: 5.8 15 Dec 2015, 21:59 UTC

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVE-2015-8241 hp vulnerability CVSS: 6.4 15 Dec 2015, 21:59 UTC

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVE-2015-7500 hp vulnerability CVSS: 5.0 15 Dec 2015, 21:59 UTC

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.

CVE-2015-7499 hp vulnerability CVSS: 5.0 15 Dec 2015, 21:59 UTC

Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.

CVE-2015-7498 hp vulnerability CVSS: 5.0 15 Dec 2015, 21:59 UTC

Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.

CVE-2015-7497 hp vulnerability CVSS: 5.0 15 Dec 2015, 21:59 UTC

Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.

CVE-2015-5312 hp vulnerability CVSS: 7.1 15 Dec 2015, 21:59 UTC

The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

CVE-2015-3196 hp vulnerability CVSS: 4.3 06 Dec 2015, 20:59 UTC

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

CVE-2015-6857 hp vulnerability CVSS: 7.2 26 Nov 2015, 03:59 UTC

Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-3138.

CVE-2015-5451 hp vulnerability CVSS: 6.8 23 Nov 2015, 03:59 UTC

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2015-5255 hp vulnerability CVSS: 4.3 18 Nov 2015, 21:59 UTC

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

CVE-2015-7942 hp vulnerability CVSS: 6.8 18 Nov 2015, 16:59 UTC

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.

CVE-2015-5441 hp vulnerability CVSS: 4.3 12 Nov 2015, 03:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-6867 hp vulnerability CVSS: 7.5 04 Nov 2015, 03:59 UTC

The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914.

CVE-2015-6030 hp vulnerability CVSS: 7.2 04 Nov 2015, 03:59 UTC

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

CVE-2015-6029 hp vulnerability CVSS: 5.0 04 Nov 2015, 03:59 UTC

HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.

CVE-2015-5444 hp vulnerability CVSS: 4.3 18 Oct 2015, 10:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-5443 hp vulnerability CVSS: 4.0 12 Oct 2015, 10:59 UTC

HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-5435 hp vulnerability CVSS: 4.0 30 Sep 2015, 01:59 UTC

Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors.

CVE-2015-5442 hp vulnerability CVSS: 4.6 29 Sep 2015, 18:59 UTC

Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.

CVE-2015-5440 hp vulnerability CVSS: 4.9 16 Sep 2015, 14:59 UTC

HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.

CVE-2015-2136 hp vulnerability CVSS: 4.0 16 Sep 2015, 14:59 UTC

HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.

CVE-2015-5426 hp vulnerability CVSS: 4.6 16 Sep 2015, 02:00 UTC

Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.

CVE-2015-2135 hp vulnerability CVSS: 10.0 31 Aug 2015, 20:59 UTC

Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2015-5368 hp vulnerability CVSS: 7.8 27 Aug 2015, 15:59 UTC

The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors.

CVE-2015-5367 hp vulnerability CVSS: 6.9 27 Aug 2015, 15:59 UTC

The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors.

CVE-2015-5433 hp vulnerability CVSS: 4.0 27 Aug 2015, 02:59 UTC

HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-5432 hp vulnerability CVSS: 7.5 27 Aug 2015, 02:59 UTC

HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

CVE-2015-5431 hp vulnerability CVSS: 6.5 27 Aug 2015, 02:59 UTC

HP Matrix Operating Environment before 7.5.0 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVE-2015-5430 hp vulnerability CVSS: 5.0 27 Aug 2015, 02:59 UTC

HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2015-5429 hp vulnerability CVSS: 7.5 27 Aug 2015, 02:59 UTC

HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5428.

CVE-2015-5428 hp vulnerability CVSS: 7.5 27 Aug 2015, 02:59 UTC

HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5429.

CVE-2015-5427 hp vulnerability CVSS: 7.5 27 Aug 2015, 02:59 UTC

HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5428 and CVE-2015-5429.

CVE-2015-5405 hp vulnerability CVSS: 6.5 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

CVE-2015-5404 hp vulnerability CVSS: 7.5 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

CVE-2015-5403 hp vulnerability CVSS: 4.0 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-2139.

CVE-2015-5402 hp vulnerability CVSS: 7.2 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows local users to gain privileges, and consequently obtain sensitive information, modify data, or cause a denial of service, via unspecified vectors.

CVE-2015-2140 hp vulnerability CVSS: 6.5 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVE-2015-2139 hp vulnerability CVSS: 4.0 27 Aug 2015, 02:59 UTC

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5403.

CVE-2015-5413 hp vulnerability CVSS: 4.0 26 Aug 2015, 18:59 UTC

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors.

CVE-2015-5412 hp vulnerability CVSS: 6.0 26 Aug 2015, 18:59 UTC

Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVE-2015-5411 hp vulnerability CVSS: 6.8 26 Aug 2015, 18:59 UTC

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-5410 hp vulnerability CVSS: 6.5 26 Aug 2015, 18:59 UTC

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors.

CVE-2015-5409 hp vulnerability CVSS: 7.5 26 Aug 2015, 18:59 UTC

Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVE-2015-3269 hp vulnerability CVSS: 5.0 25 Aug 2015, 01:59 UTC

Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVE-2015-5424 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2885.

CVE-2015-5423 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2884.

CVE-2015-5422 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2883.

CVE-2015-5421 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2881.

CVE-2015-5420 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2880.

CVE-2015-5419 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2879.

CVE-2015-5418 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2877.

CVE-2015-5417 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2876.

CVE-2015-5416 hp vulnerability CVSS: 7.5 24 Aug 2015, 22:59 UTC

Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2875.

CVE-2015-5408 hp vulnerability CVSS: 6.0 22 Aug 2015, 23:59 UTC

HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0 and 2.1 allow remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5406 and CVE-2015-5407.

CVE-2015-5407 hp vulnerability CVSS: 6.0 22 Aug 2015, 23:59 UTC

HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0 and 2.1 allow remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5406 and CVE-2015-5408.

CVE-2015-5406 hp vulnerability CVSS: 9.0 22 Aug 2015, 23:59 UTC

HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0 and 2.1 allow remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5407 and CVE-2015-5408.

CVE-2015-2137 hp vulnerability CVSS: 10.0 22 Aug 2015, 23:59 UTC

Unspecified vulnerability in HP Operations Manager i (OMi) 9.22, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2015-2132 hp vulnerability CVSS: 4.4 22 Aug 2015, 23:59 UTC

Unspecified vulnerability in the execve system-call implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.

CVE-2015-2134 hp vulnerability CVSS: 6.0 21 Jul 2015, 19:59 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVE-2015-2126 hp vulnerability CVSS: 7.2 06 Jul 2015, 14:59 UTC

Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.

CVE-2015-3113 hp vulnerability CVSS: 10.0 23 Jun 2015, 21:59 UTC

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

CVE-2015-3237 hp vulnerability CVSS: 6.4 22 Jun 2015, 19:59 UTC

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

CVE-2015-4024 hp vulnerability CVSS: 5.0 09 Jun 2015, 18:59 UTC

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.

CVE-2015-3200 hp vulnerability CVSS: 5.0 09 Jun 2015, 14:59 UTC

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

CVE-2015-2125 hp vulnerability CVSS: 4.0 07 Jun 2015, 18:59 UTC

Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

CVE-2015-2124 hp vulnerability CVSS: 7.2 05 Jun 2015, 10:59 UTC

Unspecified vulnerability in Easy Setup Wizard in HP ThinPro Linux 4.1 through 5.1 and Smart Zero Core 4.3 and 4.4 allows local users to bypass intended access restrictions and gain privileges via unknown vectors.

CVE-2015-2121 hp vulnerability CVSS: 7.8 25 May 2015, 17:59 UTC

HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.

CVE-2015-2118 hp vulnerability CVSS: 4.0 25 May 2015, 17:59 UTC

Unspecified vulnerability in the Secure Pull Print and Security Pull Print components in HP Access Control (AC) Software 12.x through 14.x before 14.1.2 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2015-2110 hp vulnerability CVSS: 10.0 25 May 2015, 17:59 UTC

Buffer overflow in HP LoadRunner 11.52 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-2120 hp vulnerability CVSS: 8.7 25 May 2015, 14:59 UTC

Unspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to gain privileges via unknown vectors, aka ZDI-CAN-2567.

CVE-2015-4000 hp vulnerability CVSS: 4.3 21 May 2015, 00:59 UTC

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVE-2015-2115 hp vulnerability CVSS: 2.7 27 Apr 2015, 16:59 UTC

Unspecified vulnerability in HP Capture and Route Software (HPCR) 1.3 before Patch 7, 1.3 FP1 before Patch 1, and 1.4 before Patch 1 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2015-2116 hp vulnerability CVSS: 9.0 27 Apr 2015, 12:59 UTC

Unspecified vulnerability in HP Storage Data Protector 7.x before 7.03 build 107 allows remote authenticated users to execute arbitrary code or cause a denial of service via unknown vectors.

CVE-2015-3148 hp vulnerability CVSS: 5.0 24 Apr 2015, 14:59 UTC

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

CVE-2015-3145 hp vulnerability CVSS: 7.5 24 Apr 2015, 14:59 UTC

The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.

CVE-2015-3143 hp vulnerability CVSS: 5.0 24 Apr 2015, 14:59 UTC

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.

CVE-2015-2114 hp vulnerability CVSS: 6.8 14 Apr 2015, 22:59 UTC

HP Support Solution Framework before 11.51.0049 allows remote attackers to download an arbitrary program onto a client machine and execute this program via unspecified vectors.

CVE-2015-2113 hp vulnerability CVSS: 10.0 14 Apr 2015, 22:59 UTC

Unspecified vulnerability in HP Easy Deploy, as distributed standalone and in HP Easy Tools before 3.0.1.1650, on HP Thin Client t5540, t5740, and t5740e devices and HP Flexible Thin Client t510, t520, t610, t620, and t820 devices allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2015-2112 hp vulnerability CVSS: 9.0 14 Apr 2015, 22:59 UTC

Unspecified vulnerability in HP Easy Deploy, as distributed standalone and in HP Easy Tools before 3.0.1.1650, on HP Thin Client t5540, t5740, and t5740e devices and HP Flexible Thin Client t510, t520, t610, t620, and t820 devices allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2015-2111 hp vulnerability CVSS: 2.1 04 Apr 2015, 01:59 UTC

Unspecified vulnerability in HP Intelligent Provisioning 1.40 through 1.60 on Windows Server 2008 R2 and 2012 allows local users to obtain sensitive information via unknown vectors.

CVE-2015-2109 hp vulnerability CVSS: 7.5 31 Mar 2015, 10:59 UTC

Unspecified vulnerability in HP Operations Orchestration 10.x allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unknown vectors.

CVE-2015-2108 hp vulnerability CVSS: 3.5 31 Mar 2015, 10:59 UTC

Unspecified vulnerability in Powershell Operations in HP Operations Orchestration 9.x and 10.x allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2015-2106 hp vulnerability CVSS: 6.4 31 Mar 2015, 10:59 UTC

Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors.

CVE-2014-7876 hp vulnerability CVSS: 10.0 31 Mar 2015, 10:59 UTC

Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Management (CM) firmware before 1.30 allows remote attackers to gain privileges, execute arbitrary code, or cause a denial of service via unknown vectors.

CVE-2015-2107 hp vulnerability CVSS: 6.8 14 Mar 2015, 01:59 UTC

HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.

CVE-2014-7884 hp vulnerability CVSS: 9.0 14 Mar 2015, 01:59 UTC

Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.

CVE-2014-7898 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

CVE-2014-7897 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSScanner.ocx for Imaging Barcode scanners, Linear Barcode scanners, Presentation Barcode scanners, Retail Integrated Barcode scanners, Wireless Barcode scanners, and 2D Value Wireless scanners.

CVE-2014-7895 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSCashDrawer.ocx for PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, Value Serial/USB Receipt printers, and USB Standard Duty cash drawers, aka ZDI-CAN-2505.

CVE-2014-7894 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSPOSPrinter.ocx for PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, and Value Serial/USB Receipt printers, aka ZDI-CAN-2506.

CVE-2014-7893 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSCheckScanner.ocx for PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, and Value Serial/USB Receipt printers, aka ZDI-CAN-2507.

CVE-2014-7892 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMSR.ocx for Mini MSR magnetic stripe readers, Retail Integrated Dual-Head MSR magnetic stripe readers, Integrated Single Head MSR w/o SRED magnetic stripe readers, Integrated Single Head w/o MSR SRED magnetic stripe readers, RP7 Single Head MSR w/o SRED magnetic stripe readers, POS keyboards, and POS keyboards with MSR, aka ZDI-CAN-2508.

CVE-2014-7891 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSPOSKeyboard.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2509.

CVE-2014-7890 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSToneIndicator.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2510.

CVE-2014-7889 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSLineDisplay.ocx for Retail RP7 VFD Customer Display monitors, Retail Integrated 2x20 Display monitors, Retail Integrated 2x20 Complex monitors, POS Pole Display monitors, Graphical POS Pole Display monitors, and LCD Pole Display monitors, aka ZDI-CAN-2511.

CVE-2014-7888 hp vulnerability CVSS: 10.0 09 Mar 2015, 17:59 UTC

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMICR.ocx for PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, and Value Serial/USB Receipt printers, aka ZDI-CAN-2512.

CVE-2014-7896 hp vulnerability CVSS: 4.3 03 Mar 2015, 11:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-7883 hp vulnerability CVSS: 5.0 15 Feb 2015, 20:59 UTC

HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.

CVE-2014-7882 hp vulnerability CVSS: 5.5 02 Feb 2015, 01:59 UTC

Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unknown vectors.

CVE-2014-7881 hp vulnerability CVSS: 4.3 15 Jan 2015, 22:59 UTC

Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-7880 hp vulnerability CVSS: 5.0 17 Dec 2014, 16:59 UTC

Multiple unspecified vulnerabilities in the POP implementation in HP OpenVMS TCP/IP 5.7 before ECO5 allow remote attackers to cause a denial of service via unspecified vectors.

CVE-2014-7879 hp vulnerability CVSS: 8.5 10 Dec 2014, 21:59 UTC

HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors.

CVE-2014-7878 hp vulnerability CVSS: 10.0 14 Nov 2014, 00:59 UTC

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.

CVE-2014-7877 hp vulnerability CVSS: 4.9 30 Oct 2014, 10:55 UTC

Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2014-7874 hp vulnerability CVSS: 6.8 19 Oct 2014, 01:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-2647 hp vulnerability CVSS: 4.3 19 Oct 2014, 01:55 UTC

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-4661 hp vulnerability CVSS: 4.3 10 Oct 2014, 01:55 UTC

Cross-site scripting (XSS) vulnerability in HP Records Manager before 7.3.5 and 8.x before 8.1 Patch 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2649 hp vulnerability CVSS: 7.5 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Operations Manager 9.20 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2014-2648 hp vulnerability CVSS: 10.0 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2014-2646 hp vulnerability CVSS: 7.2 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.

CVE-2014-2638 hp vulnerability CVSS: 7.5 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2344.

CVE-2014-2637 hp vulnerability CVSS: 7.5 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2342.

CVE-2014-2636 hp vulnerability CVSS: 7.5 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2336.

CVE-2014-2635 hp vulnerability CVSS: 7.5 10 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2343.

CVE-2014-2644 hp vulnerability CVSS: 4.3 06 Oct 2014, 01:55 UTC

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2014-2645 hp vulnerability CVSS: 4.3 05 Oct 2014, 01:55 UTC

HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.

CVE-2014-2643 hp vulnerability CVSS: 6.5 05 Oct 2014, 01:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2014-2642 hp vulnerability CVSS: 4.3 02 Oct 2014, 00:55 UTC

HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVE-2014-2641 hp vulnerability CVSS: 6.0 02 Oct 2014, 00:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-2640 hp vulnerability CVSS: 4.3 02 Oct 2014, 00:55 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2639 hp vulnerability CVSS: 4.6 28 Sep 2014, 19:55 UTC

Unspecified vulnerability in HP MPIO Device Specific Module Manager before 4.02.00 allows local users to gain privileges via unknown vectors.

CVE-2014-2624 hp vulnerability CVSS: 10.0 11 Sep 2014, 01:55 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.

CVE-2014-2634 hp vulnerability CVSS: 9.4 23 Aug 2014, 23:55 UTC

Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.

CVE-2014-2633 hp vulnerability CVSS: 6.8 23 Aug 2014, 23:55 UTC

Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-2632 hp vulnerability CVSS: 10.0 23 Aug 2014, 23:55 UTC

Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2013-6222 hp vulnerability CVSS: 4.3 23 Aug 2014, 23:55 UTC

Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2630 hp vulnerability CVSS: 4.4 12 Aug 2014, 05:01 UTC

Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.

CVE-2014-2631 hp vulnerability CVSS: 4.6 12 Aug 2014, 00:55 UTC

Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2138.

CVE-2014-2628 hp vulnerability CVSS: 4.0 12 Aug 2014, 00:55 UTC

Unspecified vulnerability in HP Enterprise Maps 1 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2014-5160 hp vulnerability CVSS: 6.4 01 Aug 2014, 11:13 UTC

Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or delete arbitrary files via an opcode-305 request. NOTE: the vendor reportedly asserts that this behavior is "by design.

CVE-2014-2627 hp vulnerability CVSS: 5.2 01 Aug 2014, 05:12 UTC

Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2013-4840 hp vulnerability CVSS: 7.8 28 Jul 2014, 17:55 UTC

Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2014-2626 hp vulnerability CVSS: 9.4 26 Jul 2014, 15:55 UTC

Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

CVE-2014-2625 hp vulnerability CVSS: 8.5 26 Jul 2014, 15:55 UTC

Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023.

CVE-2014-2623 hp vulnerability CVSS: 10.0 18 Jul 2014, 00:55 UTC

Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2014-2490 hp vulnerability CVSS: 9.3 17 Jul 2014, 05:10 UTC

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVE-2014-2622 hp vulnerability CVSS: 8.5 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote authenticated users to obtain sensitive information or modify data via unknown vectors, aka ZDI-CAN-2312.

CVE-2014-2621 hp vulnerability CVSS: 7.8 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2090.

CVE-2014-2620 hp vulnerability CVSS: 7.8 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2089.

CVE-2014-2619 hp vulnerability CVSS: 7.8 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2088.

CVE-2014-2618 hp vulnerability CVSS: 7.8 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2080.

CVE-2014-2606 hp vulnerability CVSS: 9.0 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP StoreVirtual 4000 Storage and StoreVirtual VSA 9.5 through 11.0 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2014-2605 hp vulnerability CVSS: 5.0 16 Jul 2014, 04:58 UTC

Unspecified vulnerability in HP StoreVirtual 4000 Storage and StoreVirtual VSA 9.5 through 11.0 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2014-2617 hp vulnerability CVSS: 10.0 07 Jul 2014, 11:01 UTC

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2104.

CVE-2014-2616 hp vulnerability CVSS: 7.5 07 Jul 2014, 11:01 UTC

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

CVE-2014-2615 hp vulnerability CVSS: 7.5 07 Jul 2014, 11:01 UTC

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2083.

CVE-2014-2614 hp vulnerability CVSS: 7.5 07 Jul 2014, 11:01 UTC

Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-2140.

CVE-2014-4669 hp vulnerability CVSS: 3.5 28 Jun 2014, 15:55 UTC

HP Enterprise Maps 1.00 allows remote authenticated users to read arbitrary files via a WSDL document containing an XML external entity declaration in conjunction with an entity reference within a GetQuote operation, related to an XML External Entity (XXE) issue.

CVE-2014-2613 hp vulnerability CVSS: 9.0 28 Jun 2014, 15:55 UTC

Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors.

CVE-2014-2612 hp vulnerability CVSS: 4.0 28 Jun 2014, 15:55 UTC

Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2014-2611 hp vulnerability CVSS: 9.0 19 Jun 2014, 10:50 UTC

Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code, or obtain sensitive information or delete data, via unspecified vectors, aka ZDI-CAN-2120.

CVE-2014-2610 hp vulnerability CVSS: 7.1 19 Jun 2014, 10:50 UTC

Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117.

CVE-2014-2609 hp vulnerability CVSS: 10.0 19 Jun 2014, 10:50 UTC

The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.

CVE-2013-6221 hp vulnerability CVSS: 10.0 18 Jun 2014, 16:55 UTC

Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.

CVE-2014-2607 hp vulnerability CVSS: 8.5 26 May 2014, 00:25 UTC

Unspecified vulnerability in HP Operations Manager i 9.1 through 9.13 and 9.2 through 9.24 allows remote authenticated users to execute arbitrary code by leveraging the OMi operator role.

CVE-2014-2604 hp vulnerability CVSS: 5.0 22 May 2014, 11:14 UTC

Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2014-2603 hp vulnerability CVSS: 1.7 10 May 2014, 01:55 UTC

Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-6220 hp vulnerability CVSS: 4.3 10 May 2014, 01:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2602 hp vulnerability CVSS: 6.5 08 May 2014, 10:55 UTC

Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2014-2601 hp vulnerability CVSS: 7.8 24 Apr 2014, 23:55 UTC

The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

CVE-2013-6219 hp vulnerability CVSS: 3.8 19 Apr 2014, 21:55 UTC

Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

CVE-2013-6218 hp vulnerability CVSS: 10.0 19 Apr 2014, 21:55 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2013-6215 hp vulnerability CVSS: 8.5 19 Apr 2014, 21:55 UTC

Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 10.01 and 10.10 allows remote authenticated users to execute arbitrary code via unknown vectors, aka ZDI-CAN-1977.

CVE-2013-6212 hp vulnerability CVSS: 6.5 19 Apr 2014, 21:55 UTC

Unspecified vulnerability in HP Database and Middleware Automation 10.0, 10.01, 10.10, and 10.20 before 10.20.100 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-6214 hp vulnerability CVSS: 4.0 19 Apr 2014, 04:49 UTC

Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 9.05, 10.01, and 10.10 allows remote authenticated users to obtain sensitive information via unknown vectors, aka ZDI-CAN-2042.

CVE-2013-6213 hp vulnerability CVSS: 10.0 19 Apr 2014, 04:49 UTC

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833.

CVE-2013-6216 hp vulnerability CVSS: 2.1 12 Apr 2014, 04:37 UTC

Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.

CVE-2014-2600 hp vulnerability CVSS: 4.0 05 Apr 2014, 14:55 UTC

Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.

CVE-2013-6211 hp vulnerability CVSS: 7.8 29 Mar 2014, 01:55 UTC

Unspecified vulnerability in HP StoreOnce Virtual Storage Appliance (VSA) before 3.7.2, StoreOnce 26xx and 4210 iSCSI Backup System before 3.9.0, StoreOnce 4210 FC Backup System before 3.9.0, and StoreOnce 4xxx Backup System before 3.9.0 allows remote attackers to obtain sensitive information or cause a denial of service via unknown vectors.

CVE-2013-6210 hp vulnerability CVSS: 7.5 16 Mar 2014, 14:06 UTC

Unspecified vulnerability in HP Unified Functional Testing before 12.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1932.

CVE-2013-6208 hp vulnerability CVSS: 7.2 16 Mar 2014, 14:06 UTC

Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors.

CVE-2013-6209 hp vulnerability CVSS: 4.3 14 Mar 2014, 10:55 UTC

Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2013-6206 hp vulnerability CVSS: 9.0 14 Mar 2014, 10:55 UTC

Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2013-6205 hp vulnerability CVSS: 4.1 14 Mar 2014, 10:55 UTC

Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows local users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2013-6188 hp vulnerability CVSS: 6.8 14 Mar 2014, 10:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-4846 hp vulnerability CVSS: 5.0 14 Mar 2014, 10:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2013-6207 hp vulnerability CVSS: 9.4 11 Mar 2014, 13:01 UTC

Unspecified vulnerability in the loadFileContents function in the SOAP implementation in HP SiteScope 10.1x, 11.1x, and 11.21 allows remote attackers to read arbitrary files or cause a denial of service via unknown vectors, aka ZDI-CAN-2084.

CVE-2013-6200 hp vulnerability CVSS: 6.2 11 Mar 2014, 13:01 UTC

Unspecified vulnerability in m4 in HP HP-UX B.11.23 and B.11.31 allows local users to obtain sensitive information or modify data via unknown vectors.

CVE-2013-6201 hp vulnerability CVSS: 7.5 06 Mar 2014, 11:55 UTC

Unspecified vulnerability in HP Security Management System 3.3.0, 3.5.0 before patch 1, and 3.6.0 before patch 2 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2013-6204 hp vulnerability CVSS: 7.5 26 Feb 2014, 14:55 UTC

The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, aka ZDI-CAN-2004.

CVE-2013-6203 hp vulnerability CVSS: 7.5 26 Feb 2014, 14:55 UTC

The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, aka ZDI-CAN-1656.

CVE-2013-4841 hp vulnerability CVSS: 10.0 26 Feb 2014, 14:55 UTC

Unspecified vulnerability in dbd_manager in LeftHand OS before 11.0 in HP StoreVirtual 4000 and StoreVirtual VSA Software (formerly LeftHand Virtual SAN Appliance) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1509.

CVE-2013-6202 hp vulnerability CVSS: 6.8 24 Feb 2014, 04:48 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execute arbitrary code.

CVE-2012-6108 hp vulnerability CVSS: 2.1 15 Feb 2014, 14:57 UTC

HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.

CVE-2013-5870 hp vulnerability CVSS: 6.8 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

CVE-2014-0418 hp vulnerability CVSS: 5.1 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0424.

CVE-2014-0382 hp vulnerability CVSS: 4.3 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.

CVE-2013-5906 hp vulnerability CVSS: 5.1 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.

CVE-2013-5904 hp vulnerability CVSS: 6.8 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2013-5895 hp vulnerability CVSS: 5.0 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX.

CVE-2013-6402 hp vulnerability CVSS: 2.1 05 Jan 2014, 20:55 UTC

base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.

CVE-2013-6195 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-2008.

CVE-2013-6194 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

CVE-2013-2350 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1897.

CVE-2013-2349 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1896.

CVE-2013-2348 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1892.

CVE-2013-2347 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.

CVE-2013-2346 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1870.

CVE-2013-2345 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1869.

CVE-2013-2344 hp vulnerability CVSS: 10.0 04 Jan 2014, 04:51 UTC

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1866.

CVE-2013-6198 hp vulnerability CVSS: 4.3 29 Dec 2013, 04:25 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-6197 hp vulnerability CVSS: 5.2 29 Dec 2013, 04:25 UTC

Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2013-6189 hp vulnerability CVSS: 10.0 29 Dec 2013, 04:25 UTC

Unspecified vulnerability in the Archive Query Server in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, and 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1666.

CVE-2013-6196 hp vulnerability CVSS: 3.5 21 Dec 2013, 14:22 UTC

Cross-site scripting (XSS) vulnerability in HP Autonomy Ultraseek 5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-6193 hp vulnerability CVSS: 5.0 17 Dec 2013, 15:21 UTC

Unspecified vulnerability on HP LaserJet M1522n and M2727; LaserJet Pro 100, 300, 400, CM1415fnw, CP1*, M121*, M1536dnf, and P1*; Color LaserJet CM* and CP*; and TopShot LaserJet Pro M275 printers allows remote attackers to cause a denial of service via unknown vectors.

CVE-2013-6192 hp vulnerability CVSS: 6.8 17 Dec 2013, 04:46 UTC

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-6191 hp vulnerability CVSS: 4.3 17 Dec 2013, 04:46 UTC

Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-4845 hp vulnerability CVSS: 4.3 14 Dec 2013, 22:55 UTC

Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka A909) All-in-One printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-6427 hp vulnerability CVSS: 6.8 09 Dec 2013, 18:55 UTC

upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.

CVE-2013-4844 hp vulnerability CVSS: 7.5 29 Nov 2013, 04:33 UTC

Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, 9.31, and 9.32, and ServiceCenter 6.2.8, allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2013-6852 hp vulnerability CVSS: 6.8 22 Nov 2013, 01:55 UTC

Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method.

CVE-2013-4843 hp vulnerability CVSS: 6.8 18 Nov 2013, 03:55 UTC

Unspecified vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-4842 hp vulnerability CVSS: 4.3 18 Nov 2013, 03:55 UTC

Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-4839 hp vulnerability CVSS: 7.5 04 Nov 2013, 16:55 UTC

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1851.

CVE-2013-4838 hp vulnerability CVSS: 10.0 04 Nov 2013, 16:55 UTC

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1850.

CVE-2013-4837 hp vulnerability CVSS: 10.0 04 Nov 2013, 16:55 UTC

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

CVE-2013-4836 hp vulnerability CVSS: 7.5 04 Nov 2013, 16:55 UTC

Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759.

CVE-2013-4835 hp vulnerability CVSS: 7.5 04 Nov 2013, 16:55 UTC

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

CVE-2013-4834 hp vulnerability CVSS: 7.5 04 Nov 2013, 16:55 UTC

Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1327.

CVE-2013-4833 hp vulnerability CVSS: 4.3 16 Oct 2013, 10:52 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-4832 hp vulnerability CVSS: 4.0 16 Oct 2013, 10:52 UTC

HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2013-4831 hp vulnerability CVSS: 5.5 16 Oct 2013, 10:52 UTC

HP Service Manager 9.30 through 9.32 does not properly manage privileges, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVE-2013-4830 hp vulnerability CVSS: 7.5 16 Oct 2013, 10:52 UTC

HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach.

CVE-2013-4827 hp vulnerability CVSS: 7.5 13 Oct 2013, 10:20 UTC

SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN-1664.

CVE-2013-4826 hp vulnerability CVSS: 5.0 13 Oct 2013, 10:20 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1647.

CVE-2013-4825 hp vulnerability CVSS: 7.5 13 Oct 2013, 10:20 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass intended access restrictions via unknown vectors, aka ZDI-CAN-1645.

CVE-2013-4824 hp vulnerability CVSS: 7.5 13 Oct 2013, 10:20 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

CVE-2013-4823 hp vulnerability CVSS: 5.0 13 Oct 2013, 10:20 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.

CVE-2013-4822 hp vulnerability CVSS: 10.0 13 Oct 2013, 10:20 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.

CVE-2013-4829 hp vulnerability CVSS: 1.5 04 Oct 2013, 10:44 UTC

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.

CVE-2013-4828 hp vulnerability CVSS: 4.3 04 Oct 2013, 10:44 UTC

HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices do not properly encrypt PDF documents, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2013-4821 hp vulnerability CVSS: 4.0 23 Sep 2013, 10:18 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors.

CVE-2013-4820 hp vulnerability CVSS: 2.1 23 Sep 2013, 10:18 UTC

Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.0, and IceWall File Manager 3.0 through SP4 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-4819 hp vulnerability CVSS: 3.5 23 Sep 2013, 10:18 UTC

Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-4818 hp vulnerability CVSS: 5.0 23 Sep 2013, 10:18 UTC

Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, and IceWall File Manager 3.0 through SP4 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2013-4817 hp vulnerability CVSS: 5.0 23 Sep 2013, 10:18 UTC

Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2013-4814 hp vulnerability CVSS: 4.3 23 Sep 2013, 10:18 UTC

Cross-site scripting (XSS) vulnerability in HP XP P9000 Command View Advanced Edition Suite Software 7.x before 7.5.0-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-4325 hp vulnerability CVSS: 6.9 23 Sep 2013, 10:18 UTC

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

CVE-2013-4813 hp vulnerability CVSS: 10.0 16 Sep 2013, 13:01 UTC

The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745.

CVE-2013-4811 hp vulnerability CVSS: 10.0 16 Sep 2013, 13:01 UTC

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

CVE-2013-4812 hp vulnerability CVSS: 10.0 16 Sep 2013, 13:01 UTC

UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

CVE-2013-4810 hp vulnerability CVSS: 10.0 16 Sep 2013, 13:01 UTC

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

CVE-2013-4809 hp vulnerability CVSS: 7.5 16 Sep 2013, 13:01 UTC

Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.

CVE-2013-2353 hp vulnerability CVSS: 7.8 28 Aug 2013, 13:13 UTC

Unspecified vulnerability in HP StoreOnce D2D Backup System 1.x before 1.2.19 and 2.x before 2.3.0 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2013-4808 hp vulnerability CVSS: 10.0 18 Aug 2013, 02:52 UTC

Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31 and Service Center 6.2.8 allows remote attackers to obtain privileged access via unknown vectors.

CVE-2013-4806 hp vulnerability CVSS: 7.0 12 Aug 2013, 10:58 UTC

The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2013-4807 hp vulnerability CVSS: 7.8 05 Aug 2013, 13:22 UTC

Unspecified vulnerability on the HP LaserJet Pro P1102w, P1606dn, M1212nf MFP, M1213nf MFP, M1214nfh MFP, M1216nfh MFP, M1217nfw MFP, M1218nfs MFP, and CP1025nw with firmware before 2013-07-26 20130703 allows remote attackers to modify data via unknown vectors.

CVE-2013-4805 hp vulnerability CVSS: 9.0 05 Aug 2013, 13:22 UTC

Unspecified vulnerability in HP Integrated Lights-Out 3 (aka iLO3) firmware before 1.60 and 4 (aka iLO4) firmware before 1.30 allows remote attackers to bypass authentication via unknown vectors.

CVE-2013-2367 hp vulnerability CVSS: 10.0 31 Jul 2013, 13:20 UTC

Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678.

CVE-2011-1483 hp vulnerability CVSS: 5.0 29 Jul 2013, 13:59 UTC

wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0; and JBoss Enterprise Web Platform 5.1.1 does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.

CVE-2013-4854 hp vulnerability CVSS: 7.8 29 Jul 2013, 13:59 UTC

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

CVE-2013-4801 hp vulnerability CVSS: 7.5 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1736.

CVE-2013-4800 hp vulnerability CVSS: 9.3 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735.

CVE-2013-4799 hp vulnerability CVSS: 7.6 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1734.

CVE-2013-4798 hp vulnerability CVSS: 10.0 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.

CVE-2013-4797 hp vulnerability CVSS: 7.5 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1690.

CVE-2013-2370 hp vulnerability CVSS: 7.5 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.

CVE-2013-2369 hp vulnerability CVSS: 7.5 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1670.

CVE-2013-2368 hp vulnerability CVSS: 5.0 29 Jul 2013, 13:59 UTC

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to cause a denial of service via unknown vectors, aka ZDI-CAN-1669.

CVE-2013-4802 hp vulnerability CVSS: 4.3 29 Jul 2013, 13:59 UTC

Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ZDI-CAN-1565.

CVE-2013-2365 hp vulnerability CVSS: 7.9 22 Jul 2013, 11:19 UTC

HP Database and Middleware Automation (DMA) 10.x before 10.10, when SSL is used, allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2013-2364 hp vulnerability CVSS: 3.5 22 Jul 2013, 11:19 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-2363 hp vulnerability CVSS: 5.0 22 Jul 2013, 11:19 UTC

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2356.

CVE-2013-2362 hp vulnerability CVSS: 2.1 22 Jul 2013, 11:19 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows local users to cause a denial of service via unknown vectors, aka ZDI-CAN-1676.

CVE-2013-2361 hp vulnerability CVSS: 4.3 22 Jul 2013, 11:19 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-2360 hp vulnerability CVSS: 4.0 22 Jul 2013, 11:19 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2359.

CVE-2013-2359 hp vulnerability CVSS: 4.0 22 Jul 2013, 11:19 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2358, and CVE-2013-2360.

CVE-2013-2358 hp vulnerability CVSS: 4.0 22 Jul 2013, 11:19 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2357, CVE-2013-2359, and CVE-2013-2360.

CVE-2013-2357 hp vulnerability CVSS: 4.0 22 Jul 2013, 11:19 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2013-2358, CVE-2013-2359, and CVE-2013-2360.

CVE-2013-2356 hp vulnerability CVSS: 5.0 22 Jul 2013, 11:19 UTC

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2363.

CVE-2013-2355 hp vulnerability CVSS: 5.0 22 Jul 2013, 11:19 UTC

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2012-5217.

CVE-2012-5217 hp vulnerability CVSS: 5.0 22 Jul 2013, 11:19 UTC

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2355.

CVE-2013-2351 hp vulnerability CVSS: 7.5 13 Jul 2013, 13:09 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00, 9.1x, and 9.2x allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2013-2352 hp vulnerability CVSS: 9.4 10 Jul 2013, 22:55 UTC

LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of an unused one-time password.

CVE-2013-4784 hp vulnerability CVSS: 10.0 08 Jul 2013, 22:55 UTC

The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

CVE-2013-2341 hp vulnerability CVSS: 7.1 06 Jul 2013, 13:57 UTC

Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors.

CVE-2013-2340 hp vulnerability CVSS: 10.0 06 Jul 2013, 13:57 UTC

Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors.

CVE-2013-2343 hp vulnerability CVSS: 10.0 02 Jul 2013, 21:55 UTC

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.

CVE-2013-2342 hp vulnerability CVSS: 7.7 30 Jun 2013, 19:27 UTC

The HP StoreOnce D2D backup system with software before 3.0.0 has a default password of badg3r5 for the HPSupport account, which allows remote attackers to obtain administrative access and delete data via an SSH session.

CVE-2013-2339 hp vulnerability CVSS: 4.6 30 Jun 2013, 19:27 UTC

HP Smart Zero Core 4.3 and 4.3.1 on the t410 All-in-One Smart Zero Client, t410 Smart Zero Client, t510 Flexible Thin Client, t5565z Smart Client, t610 Flexible Thin Client, and t610 PLUS Flexible Thin Client allows local users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2013-2323 hp vulnerability CVSS: 6.0 28 Jun 2013, 14:55 UTC

HP SQL/MX 3.0 through 3.2 on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to bypass intended access restrictions and modify data via unspecified vectors, aka the "SQL/MP tables" issue.

CVE-2013-2322 hp vulnerability CVSS: 3.5 28 Jun 2013, 14:55 UTC

HP SQL/MX 3.2 and earlier on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to obtain sensitive information via unspecified vectors, aka the "SQL/MP index" issue.

CVE-2013-2338 hp vulnerability CVSS: 10.0 14 Jun 2013, 19:55 UTC

Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2013-3576 hp vulnerability CVSS: 9.0 14 Jun 2013, 18:55 UTC

ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en.

CVE-2013-2337 hp vulnerability CVSS: 4.3 14 Jun 2013, 18:55 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-2336 hp vulnerability CVSS: 5.0 14 Jun 2013, 18:55 UTC

HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2013-3575 hp vulnerability CVSS: 5.0 14 Jun 2013, 13:07 UTC

hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.

CVE-2013-3574 hp vulnerability CVSS: 7.8 14 Jun 2013, 13:07 UTC

Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.

CVE-2013-3573 hp vulnerability CVSS: 10.0 14 Jun 2013, 13:07 UTC

HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.

CVE-2013-2335 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1733.

CVE-2013-2334 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1681.

CVE-2013-2333 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.

CVE-2013-2332 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1654.

CVE-2013-2331 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1652.

CVE-2013-2330 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1638.

CVE-2013-2329 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1637.

CVE-2013-2328 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1636.

CVE-2013-2327 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1635.

CVE-2013-2326 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1634.

CVE-2013-2325 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1633.

CVE-2013-2324 hp vulnerability CVSS: 10.0 06 Jun 2013, 13:02 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1629.

CVE-2013-2321 hp vulnerability CVSS: 4.3 02 May 2013, 03:31 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-5222 hp vulnerability CVSS: 5.0 02 May 2013, 03:31 UTC

HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2012-5221 hp vulnerability CVSS: 5.0 29 Apr 2013, 21:55 UTC

Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.

CVE-2012-5219 hp vulnerability CVSS: 4.3 28 Apr 2013, 03:24 UTC

Cross-site scripting (XSS) vulnerability in HP Managed Printing Administration (MPA) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-5220 hp vulnerability CVSS: 7.2 26 Apr 2013, 11:41 UTC

Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows local users to gain privileges via unknown vectors.

CVE-2012-5218 hp vulnerability CVSS: 7.2 24 Apr 2013, 10:28 UTC

HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS restrictions and boot unintended operating systems via unspecified vectors.

CVE-2012-5216 hp vulnerability CVSS: 6.8 28 Mar 2013, 23:55 UTC

Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2012-1999 hp vulnerability CVSS: 8.5 11 Mar 2013, 21:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote authenticated users to obtain sensitive information or modify data via unknown vectors.

CVE-2012-1998 hp vulnerability CVSS: 6.8 11 Mar 2013, 21:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-1997.

CVE-2012-1997 hp vulnerability CVSS: 7.5 11 Mar 2013, 21:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-1998.

CVE-2012-1996 hp vulnerability CVSS: 4.3 11 Mar 2013, 21:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to modify data via unknown vectors.

CVE-2012-1995 hp vulnerability CVSS: 3.2 11 Mar 2013, 21:55 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows local users to obtain sensitive information or modify data via unknown vectors.

CVE-2012-5215 hp vulnerability CVSS: 8.8 09 Mar 2013, 11:55 UTC

Unspecified vulnerability on the HP LaserJet Pro M1212nf, M1213nf, M1214nfh, M1216nfh, M1217nfw, and M1219nf, and HotSpot LaserJet Pro M1218nfs, with firmware before 20130211; LaserJet Pro CP1025nw with firmware before 20130212; and LaserJet Pro P1102w and P1606dn with firmware before 20130213 allows remote attackers to modify data or cause a denial of service via unknown vectors.

CVE-2012-5214 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP ServiceCenter 6.2.8 before 6.2.8.10 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2012-5213 hp vulnerability CVSS: 7.8 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1662.

CVE-2012-5212 hp vulnerability CVSS: 6.8 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1663.

CVE-2012-5210 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) TACACS+ Authentication Manager (TAM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1646.

CVE-2012-5209 hp vulnerability CVSS: 10.0 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1659.

CVE-2012-5208 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1615.

CVE-2012-5207 hp vulnerability CVSS: 9.0 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1661.

CVE-2012-5206 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1660.

CVE-2012-5205 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1650.

CVE-2012-5204 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1614.

CVE-2012-5203 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1613.

CVE-2012-5202 hp vulnerability CVSS: 7.5 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1612.

CVE-2012-5201 hp vulnerability CVSS: 10.0 09 Mar 2013, 11:55 UTC

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1611.

CVE-2012-5200 hp vulnerability CVSS: 3.5 09 Mar 2013, 11:55 UTC

Cross-site scripting (XSS) vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-0200 hp vulnerability CVSS: 1.9 06 Mar 2013, 20:55 UTC

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

CVE-2012-5199 hp vulnerability CVSS: 6.8 16 Feb 2013, 21:55 UTC

Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2012-5198 hp vulnerability CVSS: 5.0 16 Feb 2013, 21:55 UTC

Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2012-3286 hp vulnerability CVSS: 6.5 16 Feb 2013, 21:55 UTC

Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2012-3280 hp vulnerability CVSS: 6.3 13 Feb 2013, 21:55 UTC

Multiple unspecified vulnerabilities on HP NonStop Servers H06.x and J06.x allow remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via an OSS Remote Operation over an Expand connection.

CVE-2012-3285 hp vulnerability CVSS: 10.0 06 Feb 2013, 12:05 UTC

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1513.

CVE-2012-3284 hp vulnerability CVSS: 10.0 06 Feb 2013, 12:05 UTC

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1512.

CVE-2012-3283 hp vulnerability CVSS: 10.0 06 Feb 2013, 12:05 UTC

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511.

CVE-2012-3282 hp vulnerability CVSS: 10.0 06 Feb 2013, 12:05 UTC

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1468.

CVE-2012-3281 hp vulnerability CVSS: 7.8 06 Feb 2013, 12:05 UTC

Unspecified vulnerability in Device Manager in HP XP P9000 Command View Advanced Edition before 7.4.0-00 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2012-3279 hp vulnerability CVSS: 4.3 06 Feb 2013, 12:05 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-3268 hp vulnerability CVSS: 3.5 01 Feb 2013, 11:49 UTC

Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.

CVE-2012-3278 hp vulnerability CVSS: 10.0 25 Jan 2013, 18:55 UTC

Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows remote attackers to execute arbitrary code via a malformed message packet.

CVE-2012-6501 hp vulnerability CVSS: 4.3 12 Jan 2013, 04:33 UTC

The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process.

CVE-2012-3277 hp vulnerability CVSS: 5.0 13 Dec 2012, 11:53 UTC

HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows remote attackers to cause a denial of service via unspecified vectors.

CVE-2012-3276 hp vulnerability CVSS: 2.1 13 Dec 2012, 11:53 UTC

HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows local users to cause a denial of service via unspecified vectors.

CVE-2012-3275 hp vulnerability CVSS: 10.0 06 Dec 2012, 11:45 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.1x and 9.20 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2012-3274 hp vulnerability CVSS: 10.0 06 Dec 2012, 11:45 UTC

Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data.

CVE-2012-3273 hp vulnerability CVSS: 5.0 06 Dec 2012, 11:45 UTC

Multiple unspecified vulnerabilities on the HP LaserJet Pro 400 MFP M425 with firmware 20120625 and LaserJet 400 M401 with firmware 20120621 allow remote attackers to obtain sensitive information via unknown vectors.

CVE-2012-3271 hp vulnerability CVSS: 9.3 29 Nov 2012, 13:14 UTC

Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2012-3270 hp vulnerability CVSS: 10.0 07 Nov 2012, 23:55 UTC

Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3269.

CVE-2012-3269 hp vulnerability CVSS: 7.5 07 Nov 2012, 23:55 UTC

Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270.

CVE-2012-3267 hp vulnerability CVSS: 5.0 04 Oct 2012, 11:11 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2012-3266 hp vulnerability CVSS: 5.0 02 Oct 2012, 21:55 UTC

Unspecified vulnerability in IBRIX 6.1.196 through 6.1.251 on HP IBRIX X9000 Storage allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2012-3264 hp vulnerability CVSS: 7.5 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1472.

CVE-2012-3263 hp vulnerability CVSS: 10.0 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1465.

CVE-2012-3262 hp vulnerability CVSS: 10.0 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1464.

CVE-2012-3261 hp vulnerability CVSS: 10.0 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1463.

CVE-2012-3260 hp vulnerability CVSS: 10.0 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.

CVE-2012-3259 hp vulnerability CVSS: 10.0 25 Sep 2012, 11:07 UTC

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.

CVE-2011-5184 hp vulnerability CVSS: 4.3 20 Sep 2012, 10:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5) nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate. NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.

CVE-2012-3258 hp vulnerability CVSS: 10.0 19 Sep 2012, 04:53 UTC

Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2012-3257 hp vulnerability CVSS: 4.6 08 Sep 2012, 10:28 UTC

HP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors.

CVE-2012-3256 hp vulnerability CVSS: 6.8 08 Sep 2012, 10:28 UTC

Cross-site request forgery (CSRF) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2012-3255 hp vulnerability CVSS: 4.3 08 Sep 2012, 10:28 UTC

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-3254 hp vulnerability CVSS: 10.0 30 Aug 2012, 17:55 UTC

Multiple unspecified vulnerabilities in HP iNode Management Center before iNode PC 5.1 E0304 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by a stack-based buffer overflow in iNodeMngChecker.exe for a crafted 0x0A0BF007 packet.

CVE-2012-3253 hp vulnerability CVSS: 10.0 30 Aug 2012, 17:55 UTC

Multiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by an integer overflow and heap-based buffer overflow in img.exe for a crafted message packet.

CVE-2012-4362 hp vulnerability CVSS: 4.0 20 Aug 2012, 22:55 UTC

hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account, which allows remote attackers to obtain access to a management service via a login: request to TCP port 13838.

CVE-2012-4361 hp vulnerability CVSS: 7.7 20 Aug 2012, 22:55 UTC

lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter.

CVE-2012-3252 hp vulnerability CVSS: 7.8 20 Aug 2012, 22:55 UTC

Unspecified vulnerability in HP Serviceguard A.11.19 and A.11.20 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2012-2986 hp vulnerability CVSS: 7.7 20 Aug 2012, 22:55 UTC

lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first, (2) third, or (3) fourth parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4361.

CVE-2012-3251 hp vulnerability CVSS: 4.3 16 Aug 2012, 10:38 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 7.11, 9.21, and 9.30, and HP Service Center Web Tier 6.28, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-3250 hp vulnerability CVSS: 5.0 16 Aug 2012, 10:38 UTC

Unspecified vulnerability in HP Service Manager Server 7.11, 9.21, and 9.30, and HP Service Center Server 6.28, allows remote attackers to cause a denial of service via unknown vectors.

CVE-2012-3249 hp vulnerability CVSS: 4.0 16 Aug 2012, 10:38 UTC

HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2012-3248 hp vulnerability CVSS: 5.0 16 Aug 2012, 10:38 UTC

HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2012-3247 hp vulnerability CVSS: 4.9 16 Aug 2012, 10:38 UTC

Unspecified vulnerability on the HP Integrity Server BL860c i2, BL870c i2, and BL890c i2 with firmware before 26.31 and the HP Integrity Server rx2800 i2 with firmware before 26.30 allows local users to cause a denial of service via unknown vectors.

CVE-2012-2960 hp vulnerability CVSS: 4.3 08 Aug 2012, 10:26 UTC

Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.

CVE-2012-2022 hp vulnerability CVSS: 4.3 07 Aug 2012, 19:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2021 hp vulnerability CVSS: 4.3 16 Jul 2012, 20:49 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP AssetManager 5.20, 5.21, 5.22, and 9.30 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2020 hp vulnerability CVSS: 10.0 11 Jul 2012, 04:54 UTC

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.

CVE-2012-2019 hp vulnerability CVSS: 10.0 11 Jul 2012, 04:54 UTC

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.

CVE-2012-2018 hp vulnerability CVSS: 4.3 05 Jul 2012, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2017 hp vulnerability CVSS: 7.8 30 Jun 2012, 10:15 UTC

Unspecified vulnerability on HP Photosmart Wireless e-All-in-One B110, e-All-in-One D110, Plus e-All-in-One B210, eStation All-in-One C510, Ink Advantage e-All-in-One K510, and Premium Fax e-All-in-One C410 printers allows remote attackers to cause a denial of service via unknown vectors.

CVE-2012-2016 hp vulnerability CVSS: 4.9 29 Jun 2012, 22:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows local users to obtain sensitive information via unknown vectors.

CVE-2012-2015 hp vulnerability CVSS: 9.0 29 Jun 2012, 22:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote authenticated users to gain privileges and obtain sensitive information via unknown vectors.

CVE-2012-2014 hp vulnerability CVSS: 9.0 29 Jun 2012, 22:55 UTC

HP System Management Homepage (SMH) before 7.1.1 does not properly validate input, which allows remote authenticated users to have an unspecified impact via unknown vectors.

CVE-2012-2013 hp vulnerability CVSS: 7.5 29 Jun 2012, 22:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain sensitive information or modify data, via unknown vectors.

CVE-2012-2012 hp vulnerability CVSS: 10.0 29 Jun 2012, 22:55 UTC

HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

CVE-2012-2011 hp vulnerability CVSS: 4.3 13 Jun 2012, 20:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Web Jetadmin 8.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2722 hp vulnerability CVSS: 1.2 25 May 2012, 20:55 UTC

The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.

CVE-2012-2561 hp vulnerability CVSS: 10.0 21 May 2012, 20:55 UTC

HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.

CVE-2012-2010 hp vulnerability CVSS: 6.9 18 May 2012, 20:55 UTC

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

CVE-2012-1823 hp vulnerability CVSS: 7.5 11 May 2012, 10:15 UTC

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

CVE-2012-2009 hp vulnerability CVSS: 9.0 09 May 2012, 10:33 UTC

Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2012-2008 hp vulnerability CVSS: 4.3 09 May 2012, 10:33 UTC

Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2007 hp vulnerability CVSS: 7.5 09 May 2012, 10:33 UTC

SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2012-2006 hp vulnerability CVSS: 4.9 02 May 2012, 22:55 UTC

Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.

CVE-2012-2005 hp vulnerability CVSS: 4.3 02 May 2012, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2004 hp vulnerability CVSS: 8.3 02 May 2012, 22:55 UTC

Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2012-2003 hp vulnerability CVSS: 6.8 02 May 2012, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2012-2002 hp vulnerability CVSS: 8.3 02 May 2012, 22:55 UTC

Open redirect vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2012-2001 hp vulnerability CVSS: 4.3 02 May 2012, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-2000 hp vulnerability CVSS: 7.5 02 May 2012, 21:55 UTC

Multiple unspecified vulnerabilities in HP System Health Application and Command Line Utilities before 9.0.0 allow remote attackers to execute arbitrary code via unknown vectors.

CVE-2012-0134 hp vulnerability CVSS: 4.9 19 Apr 2012, 21:55 UTC

Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors.

CVE-2012-1993 hp vulnerability CVSS: 3.2 18 Apr 2012, 10:33 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows local users to modify data or obtain sensitive information via unknown vectors.

CVE-2012-0135 hp vulnerability CVSS: 3.5 18 Apr 2012, 10:33 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.

CVE-2012-0133 hp vulnerability CVSS: 3.7 12 Apr 2012, 10:45 UTC

HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card.

CVE-2011-3846 hp vulnerability CVSS: 6.8 12 Apr 2012, 10:45 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

CVE-2012-0131 hp vulnerability CVSS: 10.0 05 Apr 2012, 13:55 UTC

Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVE-2012-0130 hp vulnerability CVSS: 5.0 05 Apr 2012, 13:25 UTC

HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2012-0129 hp vulnerability CVSS: 7.6 05 Apr 2012, 13:25 UTC

HP Onboard Administrator (OA) before 3.50 allows remote attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

CVE-2012-0128 hp vulnerability CVSS: 5.8 05 Apr 2012, 13:25 UTC

HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2012-0132 hp vulnerability CVSS: 4.3 05 Apr 2012, 13:25 UTC

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-0127 hp vulnerability CVSS: 10.0 31 Mar 2012, 14:55 UTC

Unspecified vulnerability in HP Performance Manager 9.00 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2012-0126 hp vulnerability CVSS: 5.8 28 Mar 2012, 10:54 UTC

Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.

CVE-2012-0125 hp vulnerability CVSS: 3.3 28 Mar 2012, 10:54 UTC

Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.

CVE-2012-0124 hp vulnerability CVSS: 10.0 14 Mar 2012, 03:28 UTC

Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.

CVE-2012-0123 hp vulnerability CVSS: 10.0 14 Mar 2012, 03:28 UTC

Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1498.

CVE-2012-0122 hp vulnerability CVSS: 10.0 14 Mar 2012, 03:28 UTC

Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1393.

CVE-2012-0121 hp vulnerability CVSS: 10.0 14 Mar 2012, 03:28 UTC

Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1392.

CVE-2011-4791 hp vulnerability CVSS: 10.0 03 Feb 2012, 04:05 UTC

DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.

CVE-2011-4790 hp vulnerability CVSS: 9.3 02 Feb 2012, 00:55 UTC

Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2012-0697 hp vulnerability CVSS: 10.0 13 Jan 2012, 04:14 UTC

HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.

CVE-2011-4789 hp vulnerability CVSS: 10.0 13 Jan 2012, 04:14 UTC

Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is actually HP LoadRunner."

CVE-2011-4788 hp vulnerability CVSS: 7.8 13 Jan 2012, 04:14 UTC

Absolute path traversal vulnerability in the web interface on HP StorageWorks P2000 G3 MSA array systems allows remote attackers to read arbitrary files via a pathname in the URI.

CVE-2011-4785 hp vulnerability CVSS: 7.8 10 Jan 2012, 11:55 UTC

Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 printer with firmware 07.006.0, and LaserJet 2430 printer with firmware 08.113.0_I35128 allows remote attackers to read arbitrary files via unspecified vectors, a different vulnerability than CVE-2008-4419.

CVE-2011-4165 hp vulnerability CVSS: 10.0 29 Dec 2011, 19:55 UTC

Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1263.

CVE-2011-4164 hp vulnerability CVSS: 10.0 29 Dec 2011, 19:55 UTC

Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1214.

CVE-2011-4163 hp vulnerability CVSS: 10.0 29 Dec 2011, 19:55 UTC

Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1213.

CVE-2011-4834 hp vulnerability CVSS: 4.6 15 Dec 2011, 03:57 UTC

The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.

CVE-2011-4162 hp vulnerability CVSS: 7.5 05 Dec 2011, 11:55 UTC

The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.

CVE-2011-4161 hp vulnerability CVSS: 10.0 01 Dec 2011, 21:55 UTC

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

CVE-2011-4160 hp vulnerability CVSS: 3.2 24 Nov 2011, 04:01 UTC

Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors.

CVE-2011-4159 hp vulnerability CVSS: 6.8 19 Nov 2011, 03:58 UTC

Unspecified vulnerability in System Administration Manager (SAM) in EMS before A.04.20.11.04_01 on HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.

CVE-2011-4156 hp vulnerability CVSS: 4.3 16 Nov 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4155.

CVE-2011-4155 hp vulnerability CVSS: 4.3 16 Nov 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4156.

CVE-2011-4158 hp vulnerability CVSS: 4.0 16 Nov 2011, 16:55 UTC

Unspecified vulnerability in HP Directories Support for ProLiant Management Processors 3.10 and 3.20 for Integrated Lights-Out iLO2 and iLO3 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2011-4157 hp vulnerability CVSS: 10.0 16 Nov 2011, 16:55 UTC

Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.

CVE-2011-3169 hp vulnerability CVSS: 5.0 07 Nov 2011, 20:55 UTC

Unspecified vulnerability in the SMTP service implementation in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to cause a denial of service via unknown vectors.

CVE-2011-3168 hp vulnerability CVSS: 5.0 07 Nov 2011, 20:55 UTC

Unspecified vulnerability in the POP and IMAP service implementations in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2011-3164 hp vulnerability CVSS: 6.8 04 Nov 2011, 21:55 UTC

Unspecified vulnerability in HP-UX Containers (formerly HP-UX Secure Resource Partitions (SRP)) A.03.00, A.03.00.002, and A.03.01, when running with patch PHKL_42310, allows local users to gain privileges via unknown vectors.

CVE-2011-3167 hp vulnerability CVSS: 10.0 02 Nov 2011, 17:55 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

CVE-2011-3166 hp vulnerability CVSS: 10.0 02 Nov 2011, 17:55 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209.

CVE-2011-3165 hp vulnerability CVSS: 10.0 02 Nov 2011, 17:55 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208.

CVE-2011-3163 hp vulnerability CVSS: 1.2 23 Oct 2011, 10:55 UTC

HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.

CVE-2011-3162 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296.

CVE-2011-3161 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229.

CVE-2011-3160 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228.

CVE-2011-3159 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227.

CVE-2011-3158 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226.

CVE-2011-3157 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225.

CVE-2011-3156 hp vulnerability CVSS: 10.0 19 Oct 2011, 15:55 UTC

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222.

CVE-2011-3155 hp vulnerability CVSS: 6.4 12 Oct 2011, 02:52 UTC

Unspecified vulnerability in HP Onboard Administrator (OA) 3.21 through 3.31 allows remote attackers to bypass intended access restrictions via unknown vectors.

CVE-2011-2411 hp vulnerability CVSS: 9.0 02 Oct 2011, 20:55 UTC

Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2011-2412 hp vulnerability CVSS: 10.0 21 Sep 2011, 16:55 UTC

Unspecified vulnerability in HP Business Service Automation (BSA) Essentials 2.01 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2009-5098 hp vulnerability CVSS: 5.4 13 Sep 2011, 19:59 UTC

The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.

CVE-2009-5097 hp vulnerability CVSS: 7.1 13 Sep 2011, 19:59 UTC

Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.

CVE-2011-2410 hp vulnerability CVSS: 4.3 19 Aug 2011, 17:55 UTC

Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2409 hp vulnerability CVSS: 4.3 11 Aug 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2408 hp vulnerability CVSS: 4.3 11 Aug 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2407 hp vulnerability CVSS: 6.4 11 Aug 2011, 22:55 UTC

Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors.

CVE-2011-2406 hp vulnerability CVSS: 3.5 11 Aug 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2405 hp vulnerability CVSS: 7.8 11 Aug 2011, 22:55 UTC

The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.

CVE-2011-2403 hp vulnerability CVSS: 6.5 01 Aug 2011, 19:55 UTC

SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2011-2402 hp vulnerability CVSS: 4.3 01 Aug 2011, 19:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2399 hp vulnerability CVSS: 7.8 01 Aug 2011, 19:55 UTC

Unspecified vulnerability in the Media Management Daemon (mmd) in HP Data Protector 6.11 and earlier allows remote attackers to cause a denial of service via unknown vectors.

CVE-2011-2697 hp vulnerability CVSS: 6.8 29 Jul 2011, 20:55 UTC

foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.

CVE-2011-2401 hp vulnerability CVSS: 8.3 29 Jul 2011, 20:55 UTC

Session fixation vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to hijack web sessions via unspecified vectors.

CVE-2011-2400 hp vulnerability CVSS: 4.3 29 Jul 2011, 20:55 UTC

Cross-site scripting (XSS) vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-2779 hp vulnerability CVSS: 3.6 19 Jul 2011, 21:55 UTC

Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.

CVE-2011-0770 hp vulnerability CVSS: 4.3 19 Jul 2011, 20:55 UTC

Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.

CVE-2011-2398 hp vulnerability CVSS: 6.8 11 Jul 2011, 20:55 UTC

Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges or cause a denial of service via unknown vectors.

CVE-2011-1867 hp vulnerability CVSS: 10.0 11 Jul 2011, 20:55 UTC

Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via a 0x0A0BF007 packet.

CVE-2011-2608 hp vulnerability CVSS: 6.4 01 Jul 2011, 10:55 UTC

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

CVE-2011-1866 hp vulnerability CVSS: 10.0 01 Jul 2011, 10:55 UTC

Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.

CVE-2011-1865 hp vulnerability CVSS: 10.0 01 Jul 2011, 10:55 UTC

Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.

CVE-2011-1515 hp vulnerability CVSS: 5.0 01 Jul 2011, 10:55 UTC

The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (daemon exit) via a request containing crafted parameters.

CVE-2011-1514 hp vulnerability CVSS: 5.0 01 Jul 2011, 10:55 UTC

The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request containing crafted parameters.

CVE-2011-1864 hp vulnerability CVSS: 9.3 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2011-1863 hp vulnerability CVSS: 7.5 14 Jun 2011, 17:55 UTC

HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors.

CVE-2011-1862 hp vulnerability CVSS: 4.3 14 Jun 2011, 17:55 UTC

Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1861 hp vulnerability CVSS: 8.3 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.

CVE-2011-1860 hp vulnerability CVSS: 5.0 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors.

CVE-2011-1859 hp vulnerability CVSS: 5.0 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2011-1858 hp vulnerability CVSS: 4.3 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors.

CVE-2011-1857 hp vulnerability CVSS: 8.2 14 Jun 2011, 17:55 UTC

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

CVE-2011-2331 hp vulnerability CVSS: 10.0 02 Jun 2011, 20:55 UTC

Integer overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in an a packet that triggers a heap-based buffer overflow, possibly related to an "recv" field.

CVE-2011-2328 hp vulnerability CVSS: 6.8 02 Jun 2011, 20:55 UTC

Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives.

CVE-2011-1856 hp vulnerability CVSS: 4.3 16 May 2011, 18:55 UTC

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.06 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1855 hp vulnerability CVSS: 4.3 13 May 2011, 17:05 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors.

CVE-2011-1854 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

Use-after-free vulnerability in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long syslog packet, related to an exception handler.

CVE-2011-1853 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2) invalid opcode field, related to a function pointer table.

CVE-2011-1852 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

Multiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execute arbitrary code via crafted packet content accompanying a (1) DATA or (2) ERROR opcode.

CVE-2011-1851 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

Stack-based buffer overflow in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long mode field.

CVE-2011-1850 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

Stack-based buffer overflow in the logging functionality in dbman.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via vectors related to a received action.

CVE-2011-1849 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to create or overwrite files, and subsequently execute arbitrary code, via a crafted WRQ request.

CVE-2011-1848 hp vulnerability CVSS: 10.0 13 May 2011, 17:05 UTC

Stack-based buffer overflow in img.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a crafted length field in a packet.

CVE-2011-1738 hp vulnerability CVSS: 7.2 13 May 2011, 17:05 UTC

HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.

CVE-2011-1737 hp vulnerability CVSS: 4.3 13 May 2011, 17:05 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1736 hp vulnerability CVSS: 8.5 07 May 2011, 19:55 UTC

Directory traversal vulnerability in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to read arbitrary files via directory traversal sequences in a filename in a GET_FILE message.

CVE-2011-1735 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed bm message.

CVE-2011-1734 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed omniiaputil message.

CVE-2011-1733 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed HPFGConfig message.

CVE-2011-1732 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed stutil message.

CVE-2011-1731 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_INTEGUTIL message.

CVE-2011-1730 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.

CVE-2011-1729 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed GET_FILE message.

CVE-2011-1728 hp vulnerability CVSS: 10.0 07 May 2011, 19:55 UTC

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_BAR message.

CVE-2011-1727 hp vulnerability CVSS: 4.3 03 May 2011, 20:55 UTC

Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an "HTML injection" issue.

CVE-2011-1726 hp vulnerability CVSS: 4.3 03 May 2011, 20:55 UTC

Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1724 hp vulnerability CVSS: 6.0 03 May 2011, 19:55 UTC

Unspecified vulnerability in HP Virtual Server Environment before 6.3 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2011-1545 hp vulnerability CVSS: 6.8 03 May 2011, 19:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2011-1544 hp vulnerability CVSS: 6.0 03 May 2011, 19:55 UTC

Unspecified vulnerability in HP Insight Control Performance Management before 6.3 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2011-1539 hp vulnerability CVSS: 5.0 03 May 2011, 19:55 UTC

Unspecified vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2011-1538 hp vulnerability CVSS: 4.9 03 May 2011, 19:55 UTC

Open redirect vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote authenticated users to redirect other users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2011-1537 hp vulnerability CVSS: 4.3 03 May 2011, 19:55 UTC

Cross-site scripting (XSS) vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1543 hp vulnerability CVSS: 4.3 29 Apr 2011, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2011-1542 hp vulnerability CVSS: 4.3 29 Apr 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1541 hp vulnerability CVSS: 10.0 29 Apr 2011, 22:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and consequently execute arbitrary code, via unknown vectors.

CVE-2011-1540 hp vulnerability CVSS: 9.0 29 Apr 2011, 22:55 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2011-1536 hp vulnerability CVSS: 5.0 29 Apr 2011, 22:55 UTC

Unspecified vulnerability in HP Performance Insight 5.0, 5.1x. 5.2x, 5.3x, 5.4, 5.41, and 5.41.002 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2011-1535 hp vulnerability CVSS: 6.0 29 Apr 2011, 22:55 UTC

Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux) before 6.3 allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2011-1725 hp vulnerability CVSS: 5.0 27 Apr 2011, 00:55 UTC

Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2011-1534 hp vulnerability CVSS: 6.5 22 Apr 2011, 10:55 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows remote authenticated users to obtain access to processes via unknown vectors.

CVE-2009-5071 hp vulnerability CVSS: 10.0 19 Apr 2011, 19:55 UTC

Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file."

CVE-2011-1533 hp vulnerability CVSS: 4.3 15 Apr 2011, 00:55 UTC

Cross-site scripting (XSS) vulnerability on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1532 hp vulnerability CVSS: 7.5 15 Apr 2011, 00:55 UTC

Unspecified vulnerability in the SNMP component on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to obtain sensitive information or modify data via vectors related to the Embedded Web Server (EWS).

CVE-2011-1531 hp vulnerability CVSS: 4.3 15 Apr 2011, 00:55 UTC

The webscan component in the Embedded Web Server (EWS) on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to read documents on the scan surface via unspecified vectors.

CVE-2011-0898 hp vulnerability CVSS: 4.3 15 Apr 2011, 00:55 UTC

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.00 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-0897 hp vulnerability CVSS: 4.6 15 Apr 2011, 00:55 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00 allows local users to read arbitrary files via unknown vectors.

CVE-2011-0896 hp vulnerability CVSS: 6.8 15 Apr 2011, 00:55 UTC

Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors.

CVE-2011-0895 hp vulnerability CVSS: 4.0 06 Apr 2011, 17:55 UTC

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x and 8.1x allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2011-0894 hp vulnerability CVSS: 5.5 04 Apr 2011, 12:27 UTC

Unspecified vulnerability in HP Operations 9.10 on UNIX platforms allows remote authenticated users to bypass intended access restrictions via unknown vectors.

CVE-2011-0893 hp vulnerability CVSS: 4.3 04 Apr 2011, 12:27 UTC

Cross-site scripting (XSS) vulnerability in HP Operations 9.10 on UNIX platforms allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-0891 hp vulnerability CVSS: 4.4 04 Apr 2011, 12:27 UTC

Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2011-0892 hp vulnerability CVSS: 4.3 29 Mar 2011, 18:55 UTC

Cross-site scripting (XSS) vulnerability in HP Diagnostics 7.5x and 8.0x before 8.05.54.225 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2011-0890 hp vulnerability CVSS: 5.0 25 Mar 2011, 18:55 UTC

HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.

CVE-2011-0889 hp vulnerability CVSS: 10.0 16 Mar 2011, 22:55 UTC

Unspecified vulnerability in HP Client Automation Enterprise (aka HPCA or Radia Notify) 5.11, 7.2, 7.5, 7.8, and 7.9 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2011-0280 hp vulnerability CVSS: 4.3 14 Mar 2011, 19:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.

CVE-2011-0279 hp vulnerability CVSS: 2.1 07 Mar 2011, 21:00 UTC

HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.

CVE-2011-0278 hp vulnerability CVSS: 4.3 01 Mar 2011, 23:00 UTC

Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors.

CVE-2011-0924 hp vulnerability CVSS: 10.0 09 Feb 2011, 01:00 UTC

The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.

CVE-2011-0923 hp vulnerability CVSS: 10.0 09 Feb 2011, 01:00 UTC

The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."

CVE-2011-0922 hp vulnerability CVSS: 10.0 09 Feb 2011, 01:00 UTC

The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.

CVE-2011-0921 hp vulnerability CVSS: 10.0 09 Feb 2011, 01:00 UTC

crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.

CVE-2011-0277 hp vulnerability CVSS: 6.8 09 Feb 2011, 01:00 UTC

Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.

CVE-2011-0276 hp vulnerability CVSS: 10.0 02 Feb 2011, 01:00 UTC

HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.

CVE-2011-0275 hp vulnerability CVSS: 7.1 28 Jan 2011, 21:00 UTC

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2011-0273 hp vulnerability CVSS: 9.3 25 Jan 2011, 01:00 UTC

Buffer overflow in crs.exe in HP OpenView Storage Data Protector Cell Manager 6.11 allows remote attackers to execute arbitrary code via unspecified message types.

CVE-2011-0274 hp vulnerability CVSS: 4.3 24 Jan 2011, 18:00 UTC

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-0514 hp vulnerability CVSS: 5.0 20 Jan 2011, 19:00 UTC

The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash) via a packet with a large data size to TCP port 1530.

CVE-2010-4267 hp vulnerability CVSS: 7.5 20 Jan 2011, 19:00 UTC

Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.

CVE-2011-0272 hp vulnerability CVSS: 10.0 18 Jan 2011, 18:03 UTC

Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.

CVE-2011-0271 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."

CVE-2011-0270 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in input data that involves an invalid template name.

CVE-2011-0269 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long schd_select1 parameter.

CVE-2011-0268 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long text1 parameter.

CVE-2011-0267 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) schdParams or (2) nameParams parameter, a different vulnerability than CVE-2011-0266.

CVE-2011-0266 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.

CVE-2011-0265 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.

CVE-2011-0264 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Stack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long COOKIE variable.

CVE-2011-0263 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Multiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) Source Node or (2) Destination Node variable.

CVE-2011-0262 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Buffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via large values of variables to jovgraph.exe.

CVE-2011-0261 hp vulnerability CVSS: 10.0 13 Jan 2011, 19:00 UTC

Unspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a malformed displayWidth option in the arg parameter.

CVE-2010-4114 hp vulnerability CVSS: 4.3 22 Dec 2010, 21:00 UTC

Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4113 hp vulnerability CVSS: 9.3 22 Dec 2010, 21:00 UTC

Stack-based buffer overflow in HP Power Manager (HPPM) before 4.3.2 allows remote attackers to execute arbitrary code via a long Login variable to the management web server.

CVE-2010-4112 hp vulnerability CVSS: 5.0 22 Dec 2010, 21:00 UTC

HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.

CVE-2010-4111 hp vulnerability CVSS: 4.3 22 Dec 2010, 21:00 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4110 hp vulnerability CVSS: 5.7 22 Dec 2010, 21:00 UTC

Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via unknown vectors.

CVE-2010-4116 hp vulnerability CVSS: 10.0 22 Dec 2010, 01:00 UTC

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5.x before 5.2.2.1771.2 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-4115 hp vulnerability CVSS: 9.0 17 Dec 2010, 19:00 UTC

HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

CVE-2010-4109 hp vulnerability CVSS: 4.3 08 Dec 2010, 18:00 UTC

Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.

CVE-2010-4108 hp vulnerability CVSS: 6.8 08 Dec 2010, 18:00 UTC

HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows remote authenticated users to cause a denial of service via unspecified vectors.

CVE-2010-4494 hp vulnerability CVSS: 7.5 07 Dec 2010, 21:00 UTC

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

CVE-2010-4107 hp vulnerability CVSS: 7.8 17 Nov 2010, 16:00 UTC

The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

CVE-2010-4106 hp vulnerability CVSS: 6.8 02 Nov 2010, 02:26 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-4105 hp vulnerability CVSS: 6.4 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to bypass intended access restrictions, and obtain sensitive information or modify data, via unknown vectors.

CVE-2010-4104 hp vulnerability CVSS: 5.0 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-4103 hp vulnerability CVSS: 5.0 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-4102 hp vulnerability CVSS: 5.0 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Recovery before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-4101 hp vulnerability CVSS: 4.3 02 Nov 2010, 02:26 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Recovery before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4100 hp vulnerability CVSS: 5.0 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Control Performance Management before 6.1 update 2 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-4032 hp vulnerability CVSS: 6.8 02 Nov 2010, 02:26 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-4031 hp vulnerability CVSS: 8.0 02 Nov 2010, 02:26 UTC

Unspecified vulnerability in HP Insight Control Performance Management before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2010-4030 hp vulnerability CVSS: 4.3 02 Nov 2010, 02:26 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4029 hp vulnerability CVSS: 7.5 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in HP Storage Essentials before 6.3.0, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

CVE-2010-4028 hp vulnerability CVSS: 7.5 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors.

CVE-2010-4027 hp vulnerability CVSS: 5.6 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors.

CVE-2010-4026 hp vulnerability CVSS: 6.2 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in the service API in HP Palm webOS 1.4.1 allows local users to gain privileges by leveraging the ability to perform certain service calls.

CVE-2010-4025 hp vulnerability CVSS: 9.3 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in Doc Viewer in HP Palm webOS 1.4.1 allows remote attackers to execute arbitrary code via a crafted document, as demonstrated by a Word document.

CVE-2010-4024 hp vulnerability CVSS: 6.8 28 Oct 2010, 20:00 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-4023 hp vulnerability CVSS: 4.3 28 Oct 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3994 hp vulnerability CVSS: 4.3 28 Oct 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3993 hp vulnerability CVSS: 6.4 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to obtain sensitive information or modify data via unknown vectors.

CVE-2010-3992 hp vulnerability CVSS: 9.0 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2010-3991 hp vulnerability CVSS: 4.3 28 Oct 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3990 hp vulnerability CVSS: 5.0 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-3989 hp vulnerability CVSS: 6.8 28 Oct 2010, 20:00 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-3988 hp vulnerability CVSS: 5.0 28 Oct 2010, 20:00 UTC

Unspecified vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to bypass intended access restrictions and cause a denial of service via unknown vectors.

CVE-2010-3987 hp vulnerability CVSS: 4.3 28 Oct 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3985 hp vulnerability CVSS: 4.3 26 Oct 2010, 19:00 UTC

Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3986 hp vulnerability CVSS: 5.0 26 Oct 2010, 18:00 UTC

Unspecified vulnerability in HP Virtual Connect Enterprise Manager (VCEM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-3290 hp vulnerability CVSS: 6.5 23 Oct 2010, 20:39 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2010-3289 hp vulnerability CVSS: 4.3 23 Oct 2010, 20:39 UTC

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3288 hp vulnerability CVSS: 6.8 23 Oct 2010, 20:39 UTC

Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-3291 hp vulnerability CVSS: 4.3 21 Oct 2010, 19:00 UTC

Cross-site scripting (XSS) vulnerability in HP AssetCenter 5.0x through AC_5.03, and AssetManager 5.1x through AM_5.12 and 5.2x through AM_5.22, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3287 hp vulnerability CVSS: 8.3 18 Oct 2010, 17:00 UTC

Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-3286 hp vulnerability CVSS: 5.0 18 Oct 2010, 17:00 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2010-3285 hp vulnerability CVSS: 5.0 24 Sep 2010, 19:00 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2010-3284 hp vulnerability CVSS: 4.3 24 Sep 2010, 19:00 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2010-3283 hp vulnerability CVSS: 4.3 24 Sep 2010, 19:00 UTC

Open redirect vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2010-3012 hp vulnerability CVSS: 4.3 17 Sep 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue was originally assigned CVE-2010-3010 due to a CNA error.

CVE-2010-3011 hp vulnerability CVSS: 5.0 17 Sep 2010, 18:00 UTC

CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVE-2010-3010 hp vulnerability CVSS: 4.3 15 Sep 2010, 20:00 UTC

Cross-site scripting (XSS) vulnerability on the HP 3Com OfficeConnect Gigabit VPN Firewall 3CREVF100-73 with firmware before 1.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: a separate XSS issue for HP System Management Homepage (SMH) was originally assigned CVE-2010-3010 due to a CNA error, but CVE-2010-3012 is the appropriate identifier for the SMH issue.

CVE-2010-3009 hp vulnerability CVSS: 9.0 15 Sep 2010, 18:00 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) for Linux 6.0 and 6.1 allows remote authenticated users to obtain sensitive information and gain root privileges via unknown vectors.

CVE-2010-3008 hp vulnerability CVSS: 7.2 13 Sep 2010, 21:00 UTC

Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 on Windows allows local users to gain privileges or cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3007.

CVE-2010-3003 hp vulnerability CVSS: 4.3 10 Sep 2010, 18:00 UTC

Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-3007 hp vulnerability CVSS: 7.2 09 Sep 2010, 22:00 UTC

Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.

CVE-2010-3005 hp vulnerability CVSS: 6.8 08 Sep 2010, 20:00 UTC

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.

CVE-2010-3004 hp vulnerability CVSS: 7.5 08 Sep 2010, 20:00 UTC

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-2712 hp vulnerability CVSS: 6.8 30 Aug 2010, 21:00 UTC

Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.

CVE-2010-2710 hp vulnerability CVSS: 10.0 20 Aug 2010, 22:00 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-2708 hp vulnerability CVSS: 6.1 09 Aug 2010, 11:58 UTC

Unspecified vulnerability on the HP ProCurve 2610 switch before R.11.22, when DHCP is enabled, allows remote attackers to cause a denial of service via unknown vectors.

CVE-2010-2707 hp vulnerability CVSS: 8.3 09 Aug 2010, 11:58 UTC

Unspecified vulnerability on the HP ProCurve 2626 and 2650 switches before H.10.80 allows remote attackers to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.

CVE-2010-2706 hp vulnerability CVSS: 6.1 09 Aug 2010, 11:58 UTC

Unspecified vulnerability in the In-band Agent on the HP ProCurve 2610 switch before R.11.30 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2010-2705 hp vulnerability CVSS: 6.1 09 Aug 2010, 11:58 UTC

Unspecified vulnerability on the HP ProCurve 1800-24G switch with software PB.03.02 and earlier, and the ProCurve 1800-8G switch with software PA.03.02 and earlier, when SNMP is enabled, allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2010-2709 hp vulnerability CVSS: 9.3 05 Aug 2010, 18:17 UTC

Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.

CVE-2010-2704 hp vulnerability CVSS: 10.0 28 Jul 2010, 12:48 UTC

Buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long HTTP request to nnmrptconfig.exe.

CVE-2010-2703 hp vulnerability CVSS: 10.0 28 Jul 2010, 12:48 UTC

Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

CVE-2010-1973 hp vulnerability CVSS: 6.8 22 Jul 2010, 05:43 UTC

Unspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and earlier on the Itanium platform, allows local users to gain privileges or obtain sensitive information via unknown vectors.

CVE-2010-1972 hp vulnerability CVSS: 9.0 22 Jul 2010, 05:43 UTC

The default configuration of HP Client Automation (HPCA) Enterprise Infrastructure (aka Radia) allows remote attackers to read log files, and consequently cause a denial of service or have unspecified other impact, via web requests.

CVE-2010-1969 hp vulnerability CVSS: 4.3 22 Jul 2010, 05:43 UTC

Cross-site scripting (XSS) vulnerability in HP Virtual Connect Enterprise Manager for Windows before 6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2010-1971 hp vulnerability CVSS: 6.8 15 Jul 2010, 12:57 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.

CVE-2010-1970 hp vulnerability CVSS: 4.6 15 Jul 2010, 12:57 UTC

Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors.

CVE-2010-1968 hp vulnerability CVSS: 6.8 15 Jul 2010, 12:57 UTC

Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971.

CVE-2010-1967 hp vulnerability CVSS: 3.6 15 Jul 2010, 12:57 UTC

Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors.

CVE-2010-1966 hp vulnerability CVSS: 4.6 15 Jul 2010, 12:57 UTC

Unspecified vulnerability in HP Insight Control power management for Windows before 6.1 allows local users to read or modify data, or cause a denial of service, via unknown vectors.

CVE-2010-2612 hp vulnerability CVSS: 2.1 02 Jul 2010, 12:44 UTC

Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive information via unknown vectors.

CVE-2010-1964 hp vulnerability CVSS: 7.5 17 Jun 2010, 16:30 UTC

Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.

CVE-2010-1961 hp vulnerability CVSS: 10.0 10 Jun 2010, 00:30 UTC

Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.

CVE-2010-1960 hp vulnerability CVSS: 10.0 10 Jun 2010, 00:30 UTC

Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long, invalid option to jovgraph.exe.

CVE-2010-1963 hp vulnerability CVSS: 4.3 07 Jun 2010, 17:12 UTC

Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-1962 hp vulnerability CVSS: 10.0 07 Jun 2010, 17:12 UTC

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-1959 hp vulnerability CVSS: 5.0 27 May 2010, 19:30 UTC

Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.

CVE-2010-1557 hp vulnerability CVSS: 4.3 14 May 2010, 20:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP Insight Control Server Migration before 6.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-1556 hp vulnerability CVSS: 6.4 14 May 2010, 20:30 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) 5.3, 5.3 Update 1, and 6.0 allows remote attackers to obtain sensitive information and modify data via unknown vectors.

CVE-2010-1558 hp vulnerability CVSS: 4.7 14 May 2010, 19:30 UTC

Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors.

CVE-2010-1555 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.

CVE-2010-1554 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.

CVE-2010-1553 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.

CVE-2010-1552 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.

CVE-2010-1551 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the sel parameter.

CVE-2010-1550 hp vulnerability CVSS: 10.0 13 May 2010, 17:30 UTC

Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in the sel parameter.

CVE-2010-1549 hp vulnerability CVSS: 10.0 07 May 2010, 18:24 UTC

Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-1586 hp vulnerability CVSS: 4.3 28 Apr 2010, 22:30 UTC

Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.

CVE-2010-1038 hp vulnerability CVSS: 6.5 28 Apr 2010, 22:30 UTC

Unspecified vulnerability in HP System Insight Manager before 6.0 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2010-1037 hp vulnerability CVSS: 6.8 28 Apr 2010, 22:30 UTC

Cross-site request forgery (CSRF) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-1036 hp vulnerability CVSS: 4.3 28 Apr 2010, 22:30 UTC

Cross-site scripting (XSS) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-1035 hp vulnerability CVSS: 9.0 23 Apr 2010, 14:30 UTC

Multiple unspecified vulnerabilities in HP Virtual Machine Manager (VMM) before 6.0 allow remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2010-1034 hp vulnerability CVSS: 4.6 23 Apr 2010, 14:30 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6.0 before 6.0.0.96 on Windows, allows remote authenticated users to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.

CVE-2010-1033 hp vulnerability CVSS: 9.3 21 Apr 2010, 14:30 UTC

Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll.

CVE-2010-1032 hp vulnerability CVSS: 4.9 21 Apr 2010, 14:30 UTC

Unspecified vulnerability in HP HP-UX B.11.11 allows local users to cause a denial of service via unknown vectors.

CVE-2010-1031 hp vulnerability CVSS: 6.9 01 Apr 2010, 19:30 UTC

Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux or ICE-LX) 2.11 and earlier allows local users to gain privileges via unknown vectors.

CVE-2010-1030 hp vulnerability CVSS: 4.4 31 Mar 2010, 18:00 UTC

Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.

CVE-2010-0450 hp vulnerability CVSS: 8.5 31 Mar 2010, 18:00 UTC

Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote authenticated users to gain privileges via unknown vectors.

CVE-2010-0449 hp vulnerability CVSS: 4.3 31 Mar 2010, 18:00 UTC

Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2010-0448 hp vulnerability CVSS: 5.0 31 Mar 2010, 18:00 UTC

Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to obtain "unauthorized access to data" via unknown vectors.

CVE-2010-0451 hp vulnerability CVSS: 4.0 29 Mar 2010, 22:30 UTC

The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests.

CVE-2010-0446 hp vulnerability CVSS: 4.3 12 Feb 2010, 19:30 UTC

Unspecified vulnerability on the HP DreamScreen 100 and 130 with firmware before 1.6.0.0, when using a web-connected configuration, allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2010-0445 hp vulnerability CVSS: 10.0 11 Feb 2010, 17:30 UTC

Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2010-0444 hp vulnerability CVSS: 10.0 09 Feb 2010, 19:30 UTC

HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2009-4185 hp vulnerability CVSS: 4.3 05 Feb 2010, 22:30 UTC

Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.

CVE-2010-0443 hp vulnerability CVSS: 6.8 04 Feb 2010, 20:15 UTC

Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors.

CVE-2009-4184 hp vulnerability CVSS: 6.2 03 Feb 2010, 18:30 UTC

Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors.

CVE-2009-4183 hp vulnerability CVSS: 4.6 28 Jan 2010, 20:30 UTC

Unspecified vulnerability in HP OpenView Storage Data Protector 6.00 and 6.10 allows local users to obtain unspecified "access" via unknown vectors.

CVE-2009-4000 hp vulnerability CVSS: 10.0 20 Jan 2010, 22:30 UTC

Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.

CVE-2009-3999 hp vulnerability CVSS: 10.0 20 Jan 2010, 22:30 UTC

Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

CVE-2009-4182 hp vulnerability CVSS: 9.0 14 Jan 2010, 18:30 UTC

Multiple unspecified vulnerabilities in HP Web Jetadmin 10.2, when a remote SQL server is used, allow remote attackers to obtain access to data or cause a denial of service, possibly by leveraging authentication and encryption weaknesses on the SQL server.

CVE-2007-2281 hp vulnerability CVSS: 10.0 18 Dec 2009, 19:30 UTC

Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via a large value in the size parameter.

CVE-2007-2280 hp vulnerability CVSS: 10.0 18 Dec 2009, 19:30 UTC

Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.

CVE-2009-0898 hp vulnerability CVSS: 10.0 10 Dec 2009, 23:30 UTC

Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.

CVE-2009-4181 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors involving the sel and arg parameters to jovgraph.exe.

CVE-2009-4180 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Stack-based buffer overflow in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.

CVE-2009-4179 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Accept-Language header in an OVABverbose action.

CVE-2009-4178 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.

CVE-2009-4177 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.

CVE-2009-4176 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Multiple heap-based buffer overflows in ovsessionmgr.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (1) userid or (2) passwd parameter to ovlogin.exe.

CVE-2009-3849 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template parameter to nnmRptConfig.exe, related to the strcat function; or (2) a long Oid parameter to snmp.exe.

CVE-2009-3848 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Stack-based buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Template parameter, related to the vsprintf function.

CVE-2009-3847 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2009-3846 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

Multiple heap-based buffer overflows in ovlogin.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (1) userid or (2) passwd parameter.

CVE-2009-3845 hp vulnerability CVSS: 10.0 10 Dec 2009, 22:30 UTC

The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter to unspecified Perl scripts.

CVE-2009-3844 hp vulnerability CVSS: 10.0 08 Dec 2009, 23:30 UTC

Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted MSG_PROTOCOL packet.

CVE-2009-4189 hp vulnerability CVSS: 10.0 03 Dec 2009, 17:30 UTC

HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3099 and CVE-2009-3843.

CVE-2009-4188 hp vulnerability CVSS: 10.0 03 Dec 2009, 17:30 UTC

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

CVE-2009-2686 hp vulnerability CVSS: 7.2 02 Dec 2009, 16:30 UTC

Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through J06.07.01 allows local users to gain privileges, cause a denial of service, or obtain "access to data" via unknown vectors.

CVE-2009-3843 hp vulnerability CVSS: 10.0 24 Nov 2009, 00:30 UTC

HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.

CVE-2009-3842 hp vulnerability CVSS: 10.0 20 Nov 2009, 17:30 UTC

Unspecified vulnerability on the HP Color LaserJet M3530 Multifunction Printer with firmware 05.058.4 and the Color LaserJet CP3525 Printer with firmware 53.021.2 allows remote attackers to obtain "access to data" or cause a denial of service via unknown vectors.

CVE-2009-3977 hp vulnerability CVSS: 5.0 19 Nov 2009, 00:30 UTC

Multiple buffer overflows in a certain ActiveX control in ActiveDom.ocx in HP OpenView Network Node Manager (OV NNM) 7.53 might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via a long string argument to the (1) DisplayName, (2) AddGroup, (3) InstallComponent, or (4) Subscribe method. NOTE: this issue is not a vulnerability in many environments, because the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.

CVE-2009-3840 hp vulnerability CVSS: 5.0 19 Nov 2009, 00:30 UTC

The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet.

CVE-2009-3841 hp vulnerability CVSS: 9.0 17 Nov 2009, 18:30 UTC

Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2009-2678 hp vulnerability CVSS: 4.0 13 Nov 2009, 15:30 UTC

Unspecified vulnerability in Open System Services (OSS) Name Server on HP NonStop G06.27, G06.28, G06.29, G06.30, H06.06, H06.07, H06.08, and J06.03 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2009-2685 hp vulnerability CVSS: 10.0 06 Nov 2009, 15:30 UTC

Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.

CVE-2009-3693 hp vulnerability CVSS: 9.3 13 Oct 2009, 10:30 UTC

Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.

CVE-2009-2684 hp vulnerability CVSS: 4.3 13 Oct 2009, 10:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

CVE-2009-2679 hp vulnerability CVSS: 7.8 05 Oct 2009, 18:30 UTC

Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.

CVE-2009-2683 hp vulnerability CVSS: 7.1 29 Sep 2009, 18:00 UTC

Unspecified vulnerability in the Sender module in HP Remote Graphics Software (RGS) 5.1.3 through 5.2.6 allows remote authenticated users to execute arbitrary code via unknown vectors.

CVE-2009-2682 hp vulnerability CVSS: 7.2 24 Sep 2009, 18:30 UTC

Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

CVE-2009-3099 hp vulnerability CVSS: 10.0 08 Sep 2009, 18:30 UTC

Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2007-3872. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-3098 hp vulnerability CVSS: 10.0 08 Sep 2009, 18:30 UTC

Unspecified vulnerability in the Portal in HP Operations Dashboard 2.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-3097 hp vulnerability CVSS: 7.8 08 Sep 2009, 18:30 UTC

Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-3096 hp vulnerability CVSS: 10.0 08 Sep 2009, 18:30 UTC

Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a "Remote exploit" on Windows platforms, and (2) a "Remote preauthentication exploit" on the Windows Server 2003 SP2 platform, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-1427 hp vulnerability CVSS: 4.9 12 Aug 2009, 10:30 UTC

Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.

CVE-2009-1426 hp vulnerability CVSS: 7.8 29 Jul 2009, 17:30 UTC

Unspecified vulnerability on HP ProLiant DL and ML 100 Series G5, G5p, and G6 servers with ProLiant Onboard Administrator Powered by LO100i (formerly Lights Out 100) 3.07 and earlier allows remote attackers to cause a denial of service via unknown vectors.

CVE-2009-2298 hp vulnerability CVSS: 7.5 02 Jul 2009, 10:30 UTC

Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.53 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a CGI request to webappmon.exe. NOTE: this may overlap CVE-2009-1420.

CVE-2009-1421 hp vulnerability CVSS: 4.9 02 Jul 2009, 10:30 UTC

Unspecified vulnerability in NFS / ONCplus B.11.31_06 and B.11.31_07 on HP HP-UX B.11.31 allows local users to cause a denial of service via unknown attack vectors.

CVE-2009-1420 hp vulnerability CVSS: 10.0 11 Jun 2009, 15:30 UTC

Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when used with SNMP (aka HPOvNNM.HPOVSNMP) before 1.30.009 and MIB (aka HPOvNNM.HPOVMIB) before 1.30.009, allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.

CVE-2009-1419 hp vulnerability CVSS: 4.0 08 Jun 2009, 01:00 UTC

Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.

CVE-2009-1418 hp vulnerability CVSS: 4.3 19 May 2009, 19:30 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-0721 hp vulnerability CVSS: 10.0 18 May 2009, 18:30 UTC

Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2009-0714 hp vulnerability CVSS: 7.2 14 May 2009, 17:30 UTC

Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.

CVE-2009-0720 hp vulnerability CVSS: 10.0 05 May 2009, 17:30 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2009-0719 hp vulnerability CVSS: 6.0 29 Apr 2009, 15:30 UTC

Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.

CVE-2008-2438 hp vulnerability CVSS: 10.0 28 Apr 2009, 16:30 UTC

Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.

CVE-2009-0718 hp vulnerability CVSS: 10.0 21 Apr 2009, 15:30 UTC

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2009-0717 hp vulnerability CVSS: 5.0 21 Apr 2009, 15:30 UTC

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2009-0716 hp vulnerability CVSS: 7.5 21 Apr 2009, 15:30 UTC

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service or obtain "access" via unknown vectors.

CVE-2009-0715 hp vulnerability CVSS: 6.5 21 Apr 2009, 15:30 UTC

Unspecified vulnerability in Secure NaviCLI in HP Storage Essentials 6.0.2 through 6.0.4 allows remote authenticated users to obtain "access" or "extended privileges" via unknown vectors.

CVE-2009-1333 hp vulnerability CVSS: 4.3 17 Apr 2009, 14:30 UTC

Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body.

CVE-2007-4514 hp vulnerability CVSS: 5.0 15 Apr 2009, 10:30 UTC

Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.

CVE-2008-4420 hp vulnerability CVSS: 9.3 13 Apr 2009, 16:30 UTC

Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.

CVE-2009-0921 hp vulnerability CVSS: 10.0 25 Mar 2009, 01:30 UTC

Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4.

CVE-2009-0920 hp vulnerability CVSS: 7.5 25 Mar 2009, 01:30 UTC

Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.

CVE-2009-0207 hp vulnerability CVSS: 6.8 25 Mar 2009, 01:30 UTC

Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.

CVE-2009-0941 hp vulnerability CVSS: 7.6 18 Mar 2009, 21:00 UTC

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

CVE-2009-0940 hp vulnerability CVSS: 5.1 18 Mar 2009, 21:00 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

CVE-2009-0713 hp vulnerability CVSS: 5.0 11 Mar 2009, 14:19 UTC

Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2009-0712 hp vulnerability CVSS: 7.2 11 Mar 2009, 14:19 UTC

Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows local users to gain privileges via unknown vectors.

CVE-2009-0208 hp vulnerability CVSS: 10.0 26 Feb 2009, 23:30 UTC

Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2007-5289 hp vulnerability CVSS: 7.6 24 Feb 2009, 17:30 UTC

HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.

CVE-2009-0206 hp vulnerability CVSS: 4.9 08 Feb 2009, 21:30 UTC

Unspecified vulnerability in NFS in HP ONCplus B.11.31.05 and earlier for HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2008-4562 hp vulnerability CVSS: 10.0 08 Feb 2009, 21:30 UTC

Buffer overflow in the ovlaunch CGI program in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 on Windows allows remote attackers to execute arbitrary code via a crafted Host parameter. NOTE: this issue may be partially covered by CVE-2009-0205.

CVE-2008-4560 hp vulnerability CVSS: 7.8 08 Feb 2009, 21:30 UTC

HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to the nnmRptConfig.exe CGI program, which reveals the pathname of log directories; or (2) a crafted parameter in a request to the ovlaunch.exe CGI program, which reveals configuration details. NOTE: this issue may be partially covered by CVE-2009-0205.

CVE-2008-4559 hp vulnerability CVSS: 10.0 08 Feb 2009, 21:30 UTC

HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOTE: this issue may be partially covered by CVE-2009-0205.

CVE-2008-4419 hp vulnerability CVSS: 7.8 05 Feb 2009, 00:30 UTC

Directory traversal vulnerability in the HP JetDirect web administration interface in the HP-ChaiSOE 1.0 embedded web server on the LaserJet 9040mfp, LaserJet 9050mfp, and Color LaserJet 9500mfp before firmware 08.110.9; LaserJet 4345mfp and 9200C Digital Sender before firmware 09.120.9; Color LaserJet 4730mfp before firmware 46.200.9; LaserJet 2410, LaserJet 2420, and LaserJet 2430 before firmware 20080819 SPCL112A; LaserJet 4250 and LaserJet 4350 before firmware 20080819 SPCL015A; and LaserJet 9040 and LaserJet 9050 before firmware 20080819 SPCL110A allows remote attackers to read arbitrary files via directory traversal sequences in the URI.

CVE-2009-0418 hp vulnerability CVSS: 9.3 04 Feb 2009, 19:30 UTC

The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.

CVE-2009-0204 hp vulnerability CVSS: 4.3 30 Jan 2009, 19:30 UTC

Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-0122 hp vulnerability CVSS: 6.9 15 Jan 2009, 17:30 UTC

hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.

CVE-2008-0067 hp vulnerability CVSS: 10.0 08 Jan 2009, 19:30 UTC

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program.

CVE-2008-4418 hp vulnerability CVSS: 7.8 11 Dec 2008, 15:30 UTC

Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2008-5417 hp vulnerability CVSS: 2.1 10 Dec 2008, 14:00 UTC

HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.

CVE-2008-4416 hp vulnerability CVSS: 4.6 05 Dec 2008, 00:30 UTC

Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2008-5120 hp vulnerability CVSS: 10.0 18 Nov 2008, 00:30 UTC

Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

CVE-2008-4414 hp vulnerability CVSS: 7.2 07 Nov 2008, 19:35 UTC

Unspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vectors.

CVE-2008-4413 hp vulnerability CVSS: 6.2 04 Nov 2008, 18:29 UTC

Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 and B.11.23, and SMH 2.2.6 and 2.2.8 and earlier on HP-UX B.11.23 and B.11.31, allows local users to gain "unauthorized access" via unknown vectors, possibly related to temporary file permissions.

CVE-2007-4349 hp vulnerability CVSS: 4.3 23 Oct 2008, 22:00 UTC

The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference.

CVE-2007-4350 hp vulnerability CVSS: 4.3 21 Oct 2008, 18:00 UTC

Cross-site scripting (XSS) vulnerability in the management interface in HP SiteScope 9.0 build 911 allows remote attackers to inject arbitrary web script or HTML via an SNMP trap message.

CVE-2008-4412 hp vulnerability CVSS: 5.0 17 Oct 2008, 20:33 UTC

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2008-4411 hp vulnerability CVSS: 4.3 13 Oct 2008, 20:00 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663.

CVE-2008-3545 hp vulnerability CVSS: 7.8 13 Oct 2008, 20:00 UTC

Unspecified vulnerability in ovtopmd in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536, CVE-2008-3537, and CVE-2008-3544. NOTE: due to insufficient details from the vendor, it is not clear whether this is the same as CVE-2008-1853.

CVE-2008-3544 hp vulnerability CVSS: 9.0 13 Oct 2008, 20:00 UTC

Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.

CVE-2008-3543 hp vulnerability CVSS: 7.8 07 Oct 2008, 20:00 UTC

Unspecified vulnerability in NFS / ONCplus B.11.31_04 and earlier on HP-UX B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.

CVE-2008-3542 hp vulnerability CVSS: 7.8 02 Oct 2008, 18:18 UTC

Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2008-4052 hp vulnerability CVSS: 7.2 11 Sep 2008, 21:06 UTC

Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of service (crash) or gain privileges via unspecified vectors.

CVE-2008-3947 hp vulnerability CVSS: 7.2 05 Sep 2008, 16:08 UTC

DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.

CVE-2008-3946 hp vulnerability CVSS: 4.9 05 Sep 2008, 16:08 UTC

The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.

CVE-2008-3940 hp vulnerability CVSS: 4.4 05 Sep 2008, 15:08 UTC

Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.

CVE-2008-3902 hp vulnerability CVSS: 2.1 03 Sep 2008, 19:42 UTC

HP firmware 68DTT F.0D stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer, aka SSRT080104.

CVE-2008-3536 hp vulnerability CVSS: 7.8 03 Sep 2008, 14:12 UTC

Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3537.

CVE-2008-3537 hp vulnerability CVSS: 7.8 03 Sep 2008, 14:12 UTC

Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536.

CVE-2008-3538 hp vulnerability CVSS: 9.0 02 Sep 2008, 14:24 UTC

Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it should be for HP Enterprise Discovery.

CVE-2008-2940 hp vulnerability CVSS: 7.2 14 Aug 2008, 20:41 UTC

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack of validation of the device URI associated with an event message.

CVE-2008-2941 hp vulnerability CVSS: 4.9 14 Aug 2008, 20:41 UTC

The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207.

CVE-2008-1668 hp vulnerability CVSS: 10.0 13 Aug 2008, 18:41 UTC

ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.

CVE-2008-1664 hp vulnerability CVSS: 7.8 08 Aug 2008, 19:41 UTC

Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2008-1662 hp vulnerability CVSS: 10.0 01 Aug 2008, 14:41 UTC

Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."

CVE-2008-1667 hp vulnerability CVSS: 7.8 29 Jul 2008, 18:41 UTC

The Probe Builder Service (aka PBOVISServer.exe) in European Performance Systems (EPS) Probe Builder 2.2 before A.02.20.901, as used in HP OpenView Internet Services (OVIS) on Windows, allows remote attackers to kill arbitrary processes via a process ID number in an unspecified opcode.

CVE-2008-1666 hp vulnerability CVSS: 10.0 17 Jul 2008, 13:41 UTC

Unspecified vulnerability in HP Oracle for OpenView (OfO) 8.1.7, 9.1.01, 9.2, 9.2.0, 10g, and 10gR2 has unknown impact and attack vectors, possibly related to the July 2008 Oracle Critical Patch Update.

CVE-2008-1665 hp vulnerability CVSS: 9.0 17 Jul 2008, 13:41 UTC

Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors.

CVE-2008-1663 hp vulnerability CVSS: 4.3 09 Jul 2008, 00:41 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-5606 hp vulnerability CVSS: 10.0 04 Jun 2008, 20:32 UTC

Buffer overflow in the MoveFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5607.

CVE-2007-5610 hp vulnerability CVSS: 10.0 04 Jun 2008, 20:32 UTC

The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument.

CVE-2008-0953 hp vulnerability CVSS: 10.0 04 Jun 2008, 20:32 UTC

The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

CVE-2007-5605 hp vulnerability CVSS: 9.3 04 Jun 2008, 20:32 UTC

Buffer overflow in the GetFileTime function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5606, and CVE-2007-5607.

CVE-2007-5608 hp vulnerability CVSS: 9.3 04 Jun 2008, 20:32 UTC

The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to force a download of an arbitrary file onto a client machine via a URL in the first argument and a destination filename in the second argument, a different vulnerability than CVE-2008-0952 and CVE-2008-0953.

CVE-2008-0952 hp vulnerability CVSS: 9.3 04 Jun 2008, 20:32 UTC

The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

CVE-2007-5604 hp vulnerability CVSS: 7.5 04 Jun 2008, 20:32 UTC

Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.

CVE-2007-5607 hp vulnerability CVSS: 7.5 04 Jun 2008, 20:32 UTC

Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606.

CVE-2008-1661 hp vulnerability CVSS: 10.0 04 Jun 2008, 19:32 UTC

Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

CVE-2008-2390 hp vulnerability CVSS: 6.8 21 May 2008, 13:24 UTC

Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument.

CVE-2008-1660 hp vulnerability CVSS: 6.3 21 May 2008, 13:24 UTC

Unspecified vulnerability in useradd on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unspecified vectors.

CVE-2008-0713 hp vulnerability CVSS: 6.8 13 May 2008, 20:20 UTC

Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.

CVE-2008-1659 hp vulnerability CVSS: 7.2 08 May 2008, 00:20 UTC

Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors.

CVE-2008-0712 hp vulnerability CVSS: 6.8 25 Apr 2008, 19:05 UTC

Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.

CVE-2008-1852 hp vulnerability CVSS: 7.8 16 Apr 2008, 18:05 UTC

ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain requests that specify a large number of sub-arguments, which triggers a NULL pointer dereference due to memory allocation failure.

CVE-2008-0068 hp vulnerability CVSS: 5.0 16 Apr 2008, 18:05 UTC

Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.

CVE-2008-1851 hp vulnerability CVSS: 5.0 16 Apr 2008, 18:05 UTC

ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (hang) via certain requests that do not provide all required arguments.

CVE-2008-1853 hp vulnerability CVSS: 4.3 16 Apr 2008, 18:05 UTC

The ovtopmd service in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (exit) by sending a 0x36 packet (exit request).

CVE-2008-1842 hp vulnerability CVSS: 10.0 16 Apr 2008, 17:05 UTC

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.

CVE-2008-0711 hp vulnerability CVSS: 7.8 08 Apr 2008, 18:05 UTC

Unspecified vulnerability in the embedded management console in HP iLO-2 Management Processors (iLO-2 MP), as used in Integrity Servers rx2660, rx3600, and rx6600, and Integrity Blade Server model bl860c, allows remote attackers to cause a denial of service via unknown vectors.

CVE-2008-1697 hp vulnerability CVSS: 10.0 08 Apr 2008, 17:05 UTC

Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain topology/homeBaseView request. NOTE: some of these details are obtained from third party information.

CVE-2008-0709 hp vulnerability CVSS: 5.5 07 Apr 2008, 17:44 UTC

Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214.

CVE-2008-0708 hp vulnerability CVSS: 4.6 06 Apr 2008, 23:44 UTC

HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection.

CVE-2008-0706 hp vulnerability CVSS: 7.2 31 Mar 2008, 23:44 UTC

Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.

CVE-2008-0214 hp vulnerability CVSS: 7.5 08 Feb 2008, 02:00 UTC

Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors.

CVE-2008-0213 hp vulnerability CVSS: 7.5 07 Feb 2008, 22:00 UTC

Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2008-0212 hp vulnerability CVSS: 7.8 06 Feb 2008, 21:00 UTC

ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.

CVE-2008-0437 hp vulnerability CVSS: 10.0 23 Jan 2008, 22:00 UTC

Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.

CVE-2007-6425 hp vulnerability CVSS: 10.0 23 Jan 2008, 21:00 UTC

Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.

CVE-2007-6530 hp vulnerability CVSS: 9.3 27 Dec 2007, 22:46 UTC

Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.

CVE-2007-6419 hp vulnerability CVSS: 7.8 24 Dec 2007, 20:46 UTC

Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVE-2007-6519 hp vulnerability CVSS: 4.9 24 Dec 2007, 20:46 UTC

Unspecified vulnerability in the File-on-File Mounting File System (FFM) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows local users to cause a denial of service (system crash) via unspecified vectors.

CVE-2007-6513 hp vulnerability CVSS: 4.3 21 Dec 2007, 22:46 UTC

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

CVE-2007-6506 hp vulnerability CVSS: 9.3 20 Dec 2007, 23:46 UTC

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

CVE-2007-6195 hp vulnerability CVSS: 10.0 15 Dec 2007, 01:46 UTC

Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request.

CVE-2007-6343 hp vulnerability CVSS: 4.3 13 Dec 2007, 22:46 UTC

Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-6204 hp vulnerability CVSS: 10.0 13 Dec 2007, 21:46 UTC

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

CVE-2007-6331 hp vulnerability CVSS: 9.3 13 Dec 2007, 19:46 UTC

Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

CVE-2007-6332 hp vulnerability CVSS: 9.3 13 Dec 2007, 19:46 UTC

The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method.

CVE-2007-6333 hp vulnerability CVSS: 5.8 13 Dec 2007, 19:46 UTC

The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method.

CVE-2007-6194 hp vulnerability CVSS: 10.0 06 Dec 2007, 02:46 UTC

Unspecified vulnerability in HP Select Identity 4.01 before 4.01.012 and 4.1x before 4.13.003 allows remote attackers to obtain unspecified access via unknown vectors.

CVE-2007-5946 hp vulnerability CVSS: 7.2 14 Nov 2007, 01:46 UTC

Unspecified vulnerability in the Aries PA-RISC emulator on HP-UX B.11.23 and B.11.31 on the IA-64 platform allows local users to obtain unspecified access.

CVE-2007-5413 hp vulnerability CVSS: 7.8 29 Oct 2007, 22:46 UTC

httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Configuration Manager (CCM) 2.0 allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories, as demonstrated by ~root.

CVE-2007-5536 hp vulnerability CVSS: 4.9 18 Oct 2007, 00:17 UTC

Unspecified vulnerability in OpenSSL before A.00.09.07l on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to cause a denial of service via unspecified vectors.

CVE-2007-5208 hp vulnerability CVSS: 7.6 13 Oct 2007, 00:17 UTC

hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.

CVE-2007-5391 hp vulnerability CVSS: 10.0 12 Oct 2007, 10:17 UTC

Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.

CVE-2007-5302 hp vulnerability CVSS: 4.3 09 Oct 2007, 18:17 UTC

Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-5241 hp vulnerability CVSS: 5.0 06 Oct 2007, 16:17 UTC

Buffer overflow in NET$CSMACD.EXE in HP OpenVMS 8.3 and earlier allows local users to cause a denial of service (machine crash) via the "MCR MCL SHOW CSMA-CD Port * All" command, which overwrites a Non-Paged Pool Packet.

CVE-2007-5242 hp vulnerability CVSS: 4.3 06 Oct 2007, 16:17 UTC

Unspecified vulnerability in (1) SYS$EI1000.EXE and (2) SYS$EI1000_MON.EXE in HP OpenVMS 8.3 and earlier allows remote attackers to cause a denial of service (machine crash) via an "oversize" packet, which is not properly discarded if "the device has no remaining buffers after receipt of the first buffer segment."

CVE-2007-5008 hp vulnerability CVSS: 9.0 20 Sep 2007, 21:17 UTC

The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.

CVE-2007-4931 hp vulnerability CVSS: 2.1 18 Sep 2007, 18:17 UTC

HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL.

CVE-2007-4916 hp vulnerability CVSS: 10.0 17 Sep 2007, 17:17 UTC

Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

CVE-2007-4590 hp vulnerability CVSS: 3.3 29 Aug 2007, 01:17 UTC

The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.

CVE-2007-3872 hp vulnerability CVSS: 6.8 09 Aug 2007, 20:17 UTC

Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests.

CVE-2007-4241 hp vulnerability CVSS: 10.0 08 Aug 2007, 22:17 UTC

Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local Director on HP-UX 11.11i allows remote attackers to execute arbitrary code via a long string to TCP port 17781.

CVE-2007-4179 hp vulnerability CVSS: 1.5 08 Aug 2007, 01:17 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.

CVE-2007-4125 hp vulnerability CVSS: 7.1 01 Aug 2007, 16:17 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.

CVE-2007-3908 hp vulnerability CVSS: 4.6 19 Jul 2007, 17:30 UTC

Unspecified vulnerability in HP ServiceGuard for Linux for Red Hat Enterprise Linux (RHEL) 2.1 SG A.11.14.04 through A.11.14.06; RHEL 3.0 SG A.11.16.04 through A.11.16.10; and ServiceGuard Cluster Object Manager B.03.01.02 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2007-0980.

CVE-2007-3729 hp vulnerability CVSS: 5.0 12 Jul 2007, 17:30 UTC

The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid POP usernames.

CVE-2007-3730 hp vulnerability CVSS: 5.0 12 Jul 2007, 17:30 UTC

The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 does not log the source IP address or attempted username for login attempts, which might help remote attackers to avoid identification.

CVE-2007-3649 hp vulnerability CVSS: 6.8 10 Jul 2007, 17:30 UTC

Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.

CVE-2007-3554 hp vulnerability CVSS: 7.6 04 Jul 2007, 15:30 UTC

Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.

CVE-2007-3487 hp vulnerability CVSS: 6.4 29 Jun 2007, 18:30 UTC

Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.

CVE-2007-3260 hp vulnerability CVSS: 9.0 19 Jun 2007, 18:30 UTC

HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assigns the eDirectory members to the root group, which allows remote authenticated eDirectory users to gain privileges.

CVE-2007-3180 hp vulnerability CVSS: 9.4 12 Jun 2007, 17:30 UTC

Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors.

CVE-2007-3062 hp vulnerability CVSS: 4.3 06 Jun 2007, 01:30 UTC

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-2998 hp vulnerability CVSS: 4.9 04 Jun 2007, 17:30 UTC

The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.

CVE-2007-2791 hp vulnerability CVSS: 10.0 22 May 2007, 00:30 UTC

Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout.

CVE-2007-2719 hp vulnerability CVSS: 10.0 16 May 2007, 19:28 UTC

Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.

CVE-2007-2656 hp vulnerability CVSS: 7.8 14 May 2007, 23:19 UTC

Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile method.

CVE-2007-2553 hp vulnerability CVSS: 7.2 09 May 2007, 17:19 UTC

Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.

CVE-2007-2502 hp vulnerability CVSS: 7.8 04 May 2007, 01:19 UTC

Unspecified vulnerability in HP ProCurve 9300m Series switches with software 08.0.01c through 08.0.01j allows remote attackers to cause a denial of service via unknown vectors, a different switch series than CVE-2006-4015.

CVE-2007-2468 hp vulnerability CVSS: 4.9 02 May 2007, 22:19 UTC

Unspecified vulnerability in HP OpenVMS for Integrity Servers 8.2-1 and 8.3 allows local users to cause a denial of service (crash) via "Program actions relating to exceptions."

CVE-2007-2351 hp vulnerability CVSS: 7.2 30 Apr 2007, 22:19 UTC

Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.

CVE-2007-2275 hp vulnerability CVSS: 4.6 25 Apr 2007, 20:19 UTC

Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

CVE-2007-1993 hp vulnerability CVSS: 9.3 12 Apr 2007, 10:19 UTC

Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."

CVE-2007-1994 hp vulnerability CVSS: 4.9 12 Apr 2007, 10:19 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.

CVE-2007-1882 hp vulnerability CVSS: 6.5 06 Apr 2007, 01:19 UTC

qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.

CVE-2007-1819 hp vulnerability CVSS: 9.3 02 Apr 2007, 23:19 UTC

Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.

CVE-2007-1772 hp vulnerability CVSS: 7.1 30 Mar 2007, 01:19 UTC

The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.

CVE-2007-1727 hp vulnerability CVSS: 6.5 28 Mar 2007, 10:19 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.

CVE-2007-0980 hp vulnerability CVSS: 10.0 16 Feb 2007, 01:28 UTC

Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

CVE-2007-0915 hp vulnerability CVSS: 10.0 14 Feb 2007, 02:28 UTC

Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.

CVE-2007-0916 hp vulnerability CVSS: 4.9 14 Feb 2007, 02:28 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

CVE-2007-0866 hp vulnerability CVSS: 6.8 09 Feb 2007, 01:28 UTC

Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.

CVE-2007-0446 hp vulnerability CVSS: 10.0 08 Feb 2007, 23:28 UTC

Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.

CVE-2007-0819 hp vulnerability CVSS: 7.2 08 Feb 2007, 18:28 UTC

HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.

CVE-2007-0805 hp vulnerability CVSS: 2.1 07 Feb 2007, 11:28 UTC

The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.

CVE-2007-0441 hp vulnerability CVSS: 5.1 23 Jan 2007, 16:28 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2007-0396 hp vulnerability CVSS: 7.1 19 Jan 2007, 23:28 UTC

Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.

CVE-2007-0394 hp vulnerability CVSS: 4.6 19 Jan 2007, 23:28 UTC

HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.

CVE-2007-0358 hp vulnerability CVSS: 7.8 19 Jan 2007, 01:28 UTC

Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.

CVE-2007-0206 hp vulnerability CVSS: 5.0 12 Jan 2007, 01:28 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.

CVE-2007-0161 hp vulnerability CVSS: 4.1 10 Jan 2007, 00:28 UTC

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

CVE-2007-0139 hp vulnerability CVSS: 7.5 09 Jan 2007, 11:28 UTC

Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.

CVE-2006-6742 hp vulnerability CVSS: 7.8 26 Dec 2006, 23:28 UTC

Multiple buffer overflows in FTP Print Server 2.4 and 2.4.5 in HP LaserJet 5000 Series printers with firmware R.25.15 or R.25.47, and HP LaserJet 5100 Series printers with firmware V.29.12, allow remote attackers to cause a denial of service (device crash) via a long string in the (1) LIST or (2) NLST command.

CVE-2006-6608 hp vulnerability CVSS: 7.5 18 Dec 2006, 02:28 UTC

Unspecified vulnerability in SSH key based authentication in HP Integrated Lights Out (iLO) 1.70 through 1.87, and iLO 2 1.00 through 1.11, on Proliant servers, allows remote attackers to "gain unauthorized access."

CVE-2006-6418 hp vulnerability CVSS: 7.2 10 Dec 2006, 11:28 UTC

Buffer overflow in the POSIX Threads library (libpthread) on HP Tru64 UNIX 4.0F PK8, 4.0G PK4, and 5.1A PK6 allows local users to gain root privileges via a long PTHREAD_CONFIG environment variable.

CVE-2006-5782 hp vulnerability CVSS: 7.8 09 Nov 2006, 00:07 UTC

radexecd.exe in HP OpenView Client Configuraton Manager (CCM) does not require authentication before executing commands in the installation directory, which allows remote attackers to cause a denial of service (reboot) by calling radbootw.exe or create arbitrary files by calling radcrecv.

CVE-2006-5704 hp vulnerability CVSS: 6.2 04 Nov 2006, 01:07 UTC

HP NonStop Server G06.29, when running Standard Security T6533G06 before T6533G06^ABK, does not properly evaluate access permissions to OSS directories when no optional ACL entry exists, which allows local users to read arbitrary files.

CVE-2006-5558 hp vulnerability CVSS: 10.0 27 Oct 2006, 16:07 UTC

Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

CVE-2006-5556 hp vulnerability CVSS: 4.6 27 Oct 2006, 16:07 UTC

Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

CVE-2006-5557 hp vulnerability CVSS: 4.6 27 Oct 2006, 16:07 UTC

Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

CVE-2006-5452 hp vulnerability CVSS: 4.6 23 Oct 2006, 17:07 UTC

Buffer overflow in dtmail on HP Tru64 UNIX 4.0F through 5.1B and HP-UX B.11.00 through B.11.23 allows local users to execute arbitrary code via a long -a (aka attachment) argument.

CVE-2006-5300 hp vulnerability CVSS: 6.5 17 Oct 2006, 15:07 UTC

Unspecified vulnerability in HP Version Control Agent before 2.1.5 allows remote authenticated users to obtain "unauthorized access" to a remote Repository Manager account and potentially gain privileges via unspecified vectors.

CVE-2006-5151 hp vulnerability CVSS: 10.0 05 Oct 2006, 04:04 UTC

Unspecified vulnerability in HP Ignite-UX server before C.6.9.150 for HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to "gain root access" via unspecified vectors.

CVE-2006-5122 hp vulnerability CVSS: 4.9 03 Oct 2006, 04:03 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) "any field create name field" except "create new group name" or (2) any description field.

CVE-2006-5134 hp vulnerability CVSS: 4.0 03 Oct 2006, 04:03 UTC

Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to cause a denial of service (loss of connectivity to the classic interface) via attempted HTML injection into the "new monitor description" field.

CVE-2006-5091 hp vulnerability CVSS: 7.2 29 Sep 2006, 20:07 UTC

Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gain privileges or obtain "unauthorized access" via unspecified vectors.

CVE-2006-4820 hp vulnerability CVSS: 2.1 15 Sep 2006, 21:07 UTC

Unspecified vulnerability in X.25 on HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

CVE-2006-4795 hp vulnerability CVSS: 4.6 14 Sep 2006, 21:07 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.

CVE-2006-4201 hp vulnerability CVSS: 7.5 17 Aug 2006, 21:04 UTC

Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.

CVE-2006-4188 hp vulnerability CVSS: 5.0 17 Aug 2006, 00:04 UTC

Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2006-4187 hp vulnerability CVSS: 2.1 17 Aug 2006, 00:04 UTC

Unspecified vulnerability in HP-UX B.11.00, B.11.11 and B.11.23, when running in trusted mode, allows local users to cause a denial of service via unspecified vectors.

CVE-2006-4015 hp vulnerability CVSS: 5.0 07 Aug 2006, 19:04 UTC

Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with software before K.11.33 allow remote attackers to cause a denial of service (possibly memory leak or system crash) via unknown vectors.

CVE-2006-3686 hp vulnerability CVSS: 5.0 21 Jul 2006, 14:03 UTC

Unspecified vulnerability in [SYSEXE]SMPUTIL.EXE in HP OpenVMS 7.3-2 allows local users and "remote users" to cause a denial of service (crash).

CVE-2006-3335 hp vulnerability CVSS: 7.2 03 Jul 2006, 01:05 UTC

Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.

CVE-2006-3201 hp vulnerability CVSS: 4.9 23 Jun 2006, 20:06 UTC

Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

CVE-2006-3097 hp vulnerability CVSS: 4.9 20 Jun 2006, 17:02 UTC

Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

CVE-2006-2579 hp vulnerability CVSS: 7.5 24 May 2006, 23:02 UTC

Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2006-2580 hp vulnerability CVSS: 7.5 24 May 2006, 23:02 UTC

Multiple unspecified vulnerabilities in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allow remote attackers to gain privileged access, execute arbitrary commands, or create arbitrary files via unknown vectors.

CVE-2006-2574 hp vulnerability CVSS: 7.2 24 May 2006, 23:02 UTC

Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.

CVE-2006-2551 hp vulnerability CVSS: 2.1 23 May 2006, 16:06 UTC

Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local users to cause an unspecified denial of service via unknown vectors.

CVE-2006-2092 hp vulnerability CVSS: 5.0 29 Apr 2006, 10:02 UTC

Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.

CVE-2006-1774 hp vulnerability CVSS: 7.5 13 Apr 2006, 10:02 UTC

HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.

CVE-2006-1689 hp vulnerability CVSS: 7.2 11 Apr 2006, 00:02 UTC

Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.

CVE-2006-1654 hp vulnerability CVSS: 5.0 06 Apr 2006, 10:04 UTC

Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.

CVE-2006-1509 hp vulnerability CVSS: 4.9 30 Mar 2006, 01:06 UTC

/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.

CVE-2006-1389 hp vulnerability CVSS: 7.8 25 Mar 2006, 00:06 UTC

Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVE-2006-1248 hp vulnerability CVSS: 4.6 17 Mar 2006, 19:02 UTC

Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

CVE-2006-1023 hp vulnerability CVSS: 5.0 07 Mar 2006, 00:02 UTC

Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.

CVE-2006-0672 hp vulnerability CVSS: 10.0 13 Feb 2006, 22:02 UTC

Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.

CVE-2006-0656 hp vulnerability CVSS: 5.0 13 Feb 2006, 11:06 UTC

Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.

CVE-2006-0436 hp vulnerability CVSS: 7.2 26 Jan 2006, 11:07 UTC

Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.

CVE-2005-4823 hp vulnerability CVSS: 10.0 31 Dec 2005, 05:00 UTC

Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2005-4654 hp vulnerability CVSS: 6.4 31 Dec 2005, 05:00 UTC

Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.

CVE-2005-4451 hp vulnerability CVSS: 7.5 21 Dec 2005, 11:03 UTC

Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.

CVE-2005-4316 hp vulnerability CVSS: 7.8 17 Dec 2005, 11:03 UTC

HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.

CVE-2005-4090 hp vulnerability CVSS: 10.0 08 Dec 2005, 11:03 UTC

Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.

CVE-2005-3983 hp vulnerability CVSS: 7.8 04 Dec 2005, 11:03 UTC

Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all. If not, then this issue is not a vulnerability.

CVE-2005-3779 hp vulnerability CVSS: 7.2 23 Nov 2005, 01:03 UTC

Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.

CVE-2005-3670 hp vulnerability CVSS: 7.8 18 Nov 2005, 21:03 UTC

Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the HP advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVE-2005-3565 hp vulnerability CVSS: 7.5 16 Nov 2005, 07:42 UTC

Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.

CVE-2005-3564 hp vulnerability CVSS: 7.2 16 Nov 2005, 07:42 UTC

envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.

CVE-2005-3295 hp vulnerability CVSS: 2.1 23 Oct 2005, 21:02 UTC

Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."

CVE-2005-3277 hp vulnerability CVSS: 10.0 21 Oct 2005, 18:02 UTC

The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.

CVE-2005-2993 hp vulnerability CVSS: 1.7 20 Sep 2005, 20:03 UTC

Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).

CVE-2005-2988 hp vulnerability CVSS: 5.0 20 Sep 2005, 00:03 UTC

HP LaserJet 2430, and possibly other printers that use Jetdirect controls, stores information about recently printed documents without proper protection, which could allow remote attackers to obtain sensitive information via SNMP.

CVE-2005-2773 hp vulnerability CVSS: 7.5 02 Sep 2005, 23:03 UTC

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVE-2005-2552 hp vulnerability CVSS: 7.5 12 Aug 2005, 04:00 UTC

Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."

CVE-2005-2076 hp vulnerability CVSS: 2.1 29 Jun 2005, 04:00 UTC

HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

CVE-2005-1370 hp vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2005-1434 hp vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.

CVE-2005-1825 hp vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.

CVE-2005-1826 hp vulnerability CVSS: 7.5 03 May 2005, 04:00 UTC

Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.

CVE-2005-1433 hp vulnerability CVSS: 4.6 03 May 2005, 04:00 UTC

Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.

CVE-2005-1056 hp vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.

CVE-2005-1192 hp vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.

CVE-2005-0652 hp vulnerability CVSS: 2.1 02 May 2005, 04:00 UTC

Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

CVE-2005-0719 hp vulnerability CVSS: 2.1 09 Mar 2005, 05:00 UTC

Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.

CVE-2004-1029 hp vulnerability CVSS: 9.3 01 Mar 2005, 05:00 UTC

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVE-2005-0547 hp vulnerability CVSS: 4.6 24 Feb 2005, 05:00 UTC

Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."

CVE-2005-0364 hp vulnerability CVSS: 5.0 10 Feb 2005, 05:00 UTC

Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.

CVE-2004-0965 hp vulnerability CVSS: 7.2 09 Feb 2005, 05:00 UTC

stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.

CVE-2004-0940 hp vulnerability CVSS: 6.9 09 Feb 2005, 05:00 UTC

Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

CVE-2005-0224 hp vulnerability CVSS: 5.0 31 Jan 2005, 05:00 UTC

Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.

CVE-2004-0993 hp vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.

CVE-2004-0826 hp vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.

CVE-2004-0951 hp vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.

CVE-2004-1332 hp vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.

CVE-2004-1480 hp vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions.

CVE-2004-1811 hp vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.

CVE-2004-1328 hp vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.

CVE-2004-2693 hp vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.

CVE-2004-0952 hp vulnerability CVSS: 6.4 31 Dec 2004, 05:00 UTC

HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.

CVE-2004-2753 hp vulnerability CVSS: 5.6 31 Dec 2004, 05:00 UTC

Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of "files in a potentially insecure manner."

CVE-2004-2678 hp vulnerability CVSS: 5.1 31 Dec 2004, 05:00 UTC

Unspecified vulnerability in HP Tru64 UNIX 5.1B PK2(BL22) and PK3(BL24), and 5.1A PK6(BL24), when using IPsec/IKE (Internet Key Exchange) with Certificates, allows remote attackers to gain privileges via unknown attack vectors.

CVE-2004-2439 hp vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

CVE-2004-2600 hp vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVE-2004-2665 hp vulnerability CVSS: 4.9 31 Dec 2004, 05:00 UTC

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.

CVE-2004-1375 hp vulnerability CVSS: 4.6 23 Dec 2004, 05:00 UTC

Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.

CVE-2004-0079 hp vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVE-2004-0081 hp vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVE-2004-0112 hp vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVE-2004-0809 hp vulnerability CVSS: 5.0 16 Sep 2004, 04:00 UTC

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

CVE-2004-1713 hp vulnerability CVSS: 2.1 10 Aug 2004, 04:00 UTC

Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.

CVE-2004-0492 hp vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

CVE-2004-0716 hp vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.

CVE-2004-0525 hp vulnerability CVSS: 5.0 06 Aug 2004, 04:00 UTC

HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.

CVE-2004-0657 hp vulnerability CVSS: 5.0 06 Aug 2004, 04:00 UTC

Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.

CVE-2004-0709 hp vulnerability CVSS: 7.5 27 Jul 2004, 04:00 UTC

HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.

CVE-2004-0594 hp vulnerability CVSS: 5.1 27 Jul 2004, 04:00 UTC

The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.

CVE-2004-1856 hp vulnerability CVSS: 5.0 24 Mar 2004, 05:00 UTC

devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.

CVE-2004-1857 hp vulnerability CVSS: 2.1 24 Mar 2004, 05:00 UTC

Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.

CVE-2004-1082 hp vulnerability CVSS: 7.5 03 Feb 2004, 05:00 UTC

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVE-2004-1764 hp vulnerability CVSS: 7.2 14 Jan 2004, 05:00 UTC

Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.

CVE-2003-1495 hp vulnerability CVSS: 10.0 31 Dec 2003, 05:00 UTC

Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.

CVE-2003-1496 hp vulnerability CVSS: 10.0 31 Dec 2003, 05:00 UTC

Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.

CVE-2003-1362 hp vulnerability CVSS: 7.8 31 Dec 2003, 05:00 UTC

Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.

CVE-2003-1097 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

CVE-2003-1098 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.

CVE-2003-1356 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.

CVE-2003-1358 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

CVE-2003-1359 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

CVE-2003-1360 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.

CVE-2003-1375 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.

CVE-2003-1461 hp vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

CVE-2003-1087 hp vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.

CVE-2003-1493 hp vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Memory leak in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (memory exhaustion) via crafted TCP packets.

CVE-2003-1494 hp vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.

CVE-2003-1374 hp vulnerability CVSS: 4.6 31 Dec 2003, 05:00 UTC

Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.

CVE-2003-0951 hp vulnerability CVSS: 7.5 15 Dec 2003, 05:00 UTC

Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.

CVE-2003-0089 hp vulnerability CVSS: 7.2 15 Dec 2003, 05:00 UTC

Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.

CVE-2003-0914 hp vulnerability CVSS: 4.3 15 Dec 2003, 05:00 UTC

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

CVE-2003-0840 hp vulnerability CVSS: 7.2 17 Nov 2003, 05:00 UTC

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

CVE-2003-0746 hp vulnerability CVSS: 5.0 20 Oct 2003, 04:00 UTC

Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerabilities CVE-2003-0352 or CVE-2003-0605, such as the Blaster/MSblast/LovSAN worm.

CVE-2003-0694 hp vulnerability CVSS: 10.0 06 Oct 2003, 04:00 UTC

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVE-2003-0681 hp vulnerability CVSS: 7.5 06 Oct 2003, 04:00 UTC

A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

CVE-2003-0458 hp vulnerability CVSS: 4.6 18 Aug 2003, 04:00 UTC

Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.

CVE-2003-0333 hp vulnerability CVSS: 7.2 19 May 2003, 04:00 UTC

Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.

CVE-2003-0221 hp vulnerability CVSS: 7.2 12 May 2003, 04:00 UTC

The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

CVE-2003-0196 hp vulnerability CVSS: 10.0 05 May 2003, 04:00 UTC

Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.

CVE-2003-0201 hp vulnerability CVSS: 10.0 05 May 2003, 04:00 UTC

Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.

CVE-2002-1474 hp vulnerability CVSS: 5.0 22 Apr 2003, 04:00 UTC

Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.

CVE-2002-1475 hp vulnerability CVSS: 5.0 22 Apr 2003, 04:00 UTC

Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.

CVE-2002-1473 hp vulnerability CVSS: 4.6 22 Apr 2003, 04:00 UTC

Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

CVE-2002-1426 hp vulnerability CVSS: 7.8 11 Apr 2003, 04:00 UTC

HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.

CVE-2002-1408 hp vulnerability CVSS: 7.5 11 Apr 2003, 04:00 UTC

Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.

CVE-2002-1406 hp vulnerability CVSS: 7.2 11 Apr 2003, 04:00 UTC

Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."

CVE-2003-0169 hp vulnerability CVSS: 5.0 11 Apr 2003, 04:00 UTC

hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.

CVE-2002-1439 hp vulnerability CVSS: 4.6 11 Apr 2003, 04:00 UTC

Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.

CVE-2002-1409 hp vulnerability CVSS: 2.1 11 Apr 2003, 04:00 UTC

ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."

CVE-2003-0161 hp vulnerability CVSS: 10.0 02 Apr 2003, 05:00 UTC

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

CVE-2003-0085 hp vulnerability CVSS: 10.0 31 Mar 2003, 05:00 UTC

Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.

CVE-2003-0028 hp vulnerability CVSS: 7.5 25 Mar 2003, 05:00 UTC

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

CVE-2002-1337 hp vulnerability CVSS: 10.0 07 Mar 2003, 05:00 UTC

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

CVE-2003-0064 hp vulnerability CVSS: 7.5 03 Mar 2003, 05:00 UTC

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

CVE-2002-1794 hp vulnerability CVSS: 10.0 31 Dec 2002, 05:00 UTC

Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

CVE-2002-2264 hp vulnerability CVSS: 10.0 31 Dec 2002, 05:00 UTC

Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain.

CVE-2002-1617 hp vulnerability CVSS: 7.2 31 Dec 2002, 05:00 UTC

Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.

CVE-2002-2363 hp vulnerability CVSS: 7.2 31 Dec 2002, 05:00 UTC

VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.

CVE-2002-2263 hp vulnerability CVSS: 6.6 31 Dec 2002, 05:00 UTC

The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files.

CVE-2002-1784 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

Unknown vulnerability in inetd in HP Tru64 Unix 4.0f through 5.1a allows remote attackers to cause a denial of service via unknown attack vectors.

CVE-2002-1793 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

HTTP Server mod_ssl module running on HP-UX 11.04 with Virtualvault OS (VVOS) 4.5 through 4.6 closes the connection when the Apache server times out during an SSL request, which may allow attackers to cause a denial of service.

CVE-2002-1856 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVE-2002-1999 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests.

CVE-2002-2138 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139.

CVE-2002-2262 hp vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.

CVE-2002-1796 hp vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.

CVE-2002-1797 hp vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer.

CVE-2002-2270 hp vulnerability CVSS: 3.6 31 Dec 2002, 05:00 UTC

Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.

CVE-2002-1668 hp vulnerability CVSS: 2.1 31 Dec 2002, 05:00 UTC

HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.

CVE-2002-1318 hp vulnerability CVSS: 10.0 11 Dec 2002, 05:00 UTC

Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.

CVE-2002-1317 hp vulnerability CVSS: 7.5 11 Dec 2002, 05:00 UTC

Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.

CVE-2002-0711 hp vulnerability CVSS: 5.0 12 Nov 2002, 05:00 UTC

Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

CVE-2002-1232 hp vulnerability CVSS: 5.0 04 Nov 2002, 05:00 UTC

Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

CVE-2002-0836 hp vulnerability CVSS: 7.5 28 Oct 2002, 05:00 UTC

dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.

CVE-2002-1618 hp vulnerability CVSS: 7.2 16 Oct 2002, 04:00 UTC

JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.

CVE-2002-1147 hp vulnerability CVSS: 7.1 11 Oct 2002, 04:00 UTC

The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.

CVE-2002-1048 hp vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.

CVE-2002-0991 hp vulnerability CVSS: 7.2 04 Oct 2002, 04:00 UTC

Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.

CVE-2002-0835 hp vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones.

CVE-2002-1134 hp vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.

CVE-2002-0993 hp vulnerability CVSS: 4.6 04 Oct 2002, 04:00 UTC

Unknown vulnerability in HP Instant Support Enterprise Edition (ISEE) product U2512A for HP-UX 11.00 and 11.11 may allow authenticated users to access restricted files.

CVE-2002-0992 hp vulnerability CVSS: 2.1 04 Oct 2002, 04:00 UTC

Unknown vulnerability in IPV6 functionality for DCE daemons (1) dced or (2) rpcd on HP-UX 11.11 allows attackers to cause a denial of service (crash) via an attack that modifies internal data.

CVE-2002-1612 hp vulnerability CVSS: 7.2 13 Sep 2002, 04:00 UTC

Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

CVE-2002-1615 hp vulnerability CVSS: 7.2 13 Sep 2002, 04:00 UTC

Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.

CVE-2002-1613 hp vulnerability CVSS: 7.2 10 Sep 2002, 04:00 UTC

Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

CVE-2002-1614 hp vulnerability CVSS: 7.2 09 Sep 2002, 04:00 UTC

Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.

CVE-2002-0679 hp vulnerability CVSS: 10.0 05 Sep 2002, 04:00 UTC

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

CVE-2002-1604 hp vulnerability CVSS: 7.5 02 Sep 2002, 04:00 UTC

Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.

CVE-2002-1605 hp vulnerability CVSS: 7.5 02 Sep 2002, 04:00 UTC

Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variable to (1) dxpause, (2) dxconsole, or (3) dtsession.

CVE-2002-1607 hp vulnerability CVSS: 4.6 31 Aug 2002, 04:00 UTC

Buffer overflow in ypmatch in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.

CVE-2002-1608 hp vulnerability CVSS: 4.6 31 Aug 2002, 04:00 UTC

Buffer overflow in traceroute in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.

CVE-2002-1606 hp vulnerability CVSS: 4.6 30 Aug 2002, 04:00 UTC

Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain privileges via (1) lpc, (2) lpd, (3) lpq, (4) lpr, or (5) lprm.

CVE-2002-1609 hp vulnerability CVSS: 4.6 30 Aug 2002, 04:00 UTC

Buffer overflow in binmail in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

CVE-2002-1611 hp vulnerability CVSS: 4.6 30 Aug 2002, 04:00 UTC

Buffer overflow in quot in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

CVE-2002-1610 hp vulnerability CVSS: 2.1 30 Aug 2002, 04:00 UTC

Unknown vulnerability in ping in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to cause a denial of service.

CVE-2002-0763 hp vulnerability CVSS: 7.5 12 Aug 2002, 04:00 UTC

Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.

CVE-2002-0529 hp vulnerability CVSS: 6.2 12 Aug 2002, 04:00 UTC

HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a Trojan horse.

CVE-2002-0638 hp vulnerability CVSS: 6.2 12 Aug 2002, 04:00 UTC

setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.

CVE-2002-0798 hp vulnerability CVSS: 2.1 12 Aug 2002, 04:00 UTC

Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.

CVE-2002-1616 hp vulnerability CVSS: 7.2 01 Aug 2002, 04:00 UTC

Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.

CVE-2002-0677 hp vulnerability CVSS: 7.5 23 Jul 2002, 04:00 UTC

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

CVE-2002-0678 hp vulnerability CVSS: 7.2 23 Jul 2002, 04:00 UTC

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

CVE-2002-0350 hp vulnerability CVSS: 7.8 25 Jun 2002, 04:00 UTC

HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.

CVE-2002-0610 hp vulnerability CVSS: 7.5 18 Jun 2002, 04:00 UTC

Vulnerability in FTPSRVR in HP MPE/iX 6.0 through 7.0 does not properly validate certain FTP commands, which allows attackers to gain privileges.

CVE-2002-0585 hp vulnerability CVSS: 5.0 18 Jun 2002, 04:00 UTC

Unknown vulnerability in ndd for HP-UX 11.11 with certain TRANSPORT patches allows attackers to cause a denial of service.

CVE-2002-0609 hp vulnerability CVSS: 5.0 18 Jun 2002, 04:00 UTC

Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.

CVE-2002-0577 hp vulnerability CVSS: 2.1 18 Jun 2002, 04:00 UTC

Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.

CVE-2002-0279 hp vulnerability CVSS: 4.6 31 May 2002, 04:00 UTC

The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.

CVE-2002-0250 hp vulnerability CVSS: 7.5 29 May 2002, 04:00 UTC

Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.

CVE-2002-0076 hp vulnerability CVSS: 7.5 19 Mar 2002, 05:00 UTC

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

CVE-2003-0061 hp vulnerability CVSS: 7.2 11 Jan 2002, 05:00 UTC

Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.

CVE-2001-1563 hp vulnerability CVSS: 7.5 31 Dec 2001, 05:00 UTC

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

CVE-2001-1506 hp vulnerability CVSS: 4.6 31 Dec 2001, 05:00 UTC

Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.

CVE-2001-1509 hp vulnerability CVSS: 4.6 31 Dec 2001, 05:00 UTC

geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.

CVE-2001-1564 hp vulnerability CVSS: 2.1 31 Dec 2001, 05:00 UTC

setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available disk space.

CVE-2001-1198 hp vulnerability CVSS: 7.2 15 Dec 2001, 05:00 UTC

RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.

CVE-2001-0797 hp vulnerability CVSS: 10.0 12 Dec 2001, 05:00 UTC

Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

CVE-2001-0817 hp vulnerability CVSS: 10.0 06 Dec 2001, 05:00 UTC

Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.

CVE-2001-0809 hp vulnerability CVSS: 2.1 06 Dec 2001, 05:00 UTC

Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.

CVE-2001-0772 hp vulnerability CVSS: 4.6 18 Oct 2001, 04:00 UTC

Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.

CVE-2001-1123 hp vulnerability CVSS: 7.2 01 Oct 2001, 04:00 UTC

Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

CVE-2001-1124 hp vulnerability CVSS: 5.0 01 Oct 2001, 04:00 UTC

rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.

CVE-2001-0552 hp vulnerability CVSS: 10.0 20 Sep 2001, 04:00 UTC

ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.

CVE-2001-0668 hp vulnerability CVSS: 7.5 20 Sep 2001, 04:00 UTC

Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.

CVE-2001-1136 hp vulnerability CVSS: 2.1 13 Sep 2001, 04:00 UTC

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

CVE-2001-0978 hp vulnerability CVSS: 7.5 03 Sep 2001, 04:00 UTC

login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.

CVE-2001-0979 hp vulnerability CVSS: 7.2 03 Sep 2001, 04:00 UTC

Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.

CVE-2001-0981 hp vulnerability CVSS: 10.0 31 Aug 2001, 04:00 UTC

HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.

CVE-2001-1039 hp vulnerability CVSS: 7.5 31 Aug 2001, 04:00 UTC

The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.

CVE-2001-0976 hp vulnerability CVSS: 7.2 31 Aug 2001, 04:00 UTC

Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.

CVE-2001-1040 hp vulnerability CVSS: 6.4 31 Aug 2001, 04:00 UTC

HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.

CVE-2001-0608 hp vulnerability CVSS: 7.5 22 Aug 2001, 04:00 UTC

HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program.

CVE-2001-0606 hp vulnerability CVSS: 5.0 22 Aug 2001, 04:00 UTC

Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.

CVE-2001-0607 hp vulnerability CVSS: 4.6 22 Aug 2001, 04:00 UTC

asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.

CVE-2001-0629 hp vulnerability CVSS: 10.0 14 Aug 2001, 04:00 UTC

HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.

CVE-2001-1264 hp vulnerability CVSS: 10.0 19 Jul 2001, 04:00 UTC

Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.

CVE-2001-1182 hp vulnerability CVSS: 7.2 17 Jul 2001, 04:00 UTC

Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.

CVE-2001-1181 hp vulnerability CVSS: 7.2 16 Jul 2001, 04:00 UTC

Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.

CVE-2001-1244 hp vulnerability CVSS: 5.0 07 Jul 2001, 04:00 UTC

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

CVE-2001-0488 hp vulnerability CVSS: 2.1 27 Jun 2001, 04:00 UTC

pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.

CVE-2001-1162 hp vulnerability CVSS: 10.0 23 Jun 2001, 04:00 UTC

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

CVE-2001-0248 hp vulnerability CVSS: 10.0 18 Jun 2001, 04:00 UTC

Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.

CVE-2001-0249 hp vulnerability CVSS: 10.0 18 Jun 2001, 04:00 UTC

Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.

CVE-2001-0379 hp vulnerability CVSS: 4.6 18 Jun 2001, 04:00 UTC

Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.

CVE-2001-1256 hp vulnerability CVSS: 1.2 11 Jun 2001, 04:00 UTC

kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.

CVE-2001-0311 hp vulnerability CVSS: 4.6 02 Jun 2001, 04:00 UTC

Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.

CVE-2001-0551 hp vulnerability CVSS: 7.2 22 May 2001, 04:00 UTC

Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.

CVE-2001-0266 hp vulnerability CVSS: 7.2 03 May 2001, 04:00 UTC

Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.

CVE-2001-0267 hp vulnerability CVSS: 7.2 03 May 2001, 04:00 UTC

NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.

CVE-2001-0278 hp vulnerability CVSS: 4.6 03 May 2001, 04:00 UTC

Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.

CVE-2001-0219 hp vulnerability CVSS: 2.1 26 Mar 2001, 05:00 UTC

Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.

CVE-2001-1439 hp vulnerability CVSS: 2.1 16 Feb 2001, 05:00 UTC

Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.

CVE-2001-0085 hp vulnerability CVSS: 7.2 12 Feb 2001, 05:00 UTC

Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.

CVE-2001-0106 hp vulnerability CVSS: 5.0 12 Feb 2001, 05:00 UTC

Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.

CVE-2001-0079 hp vulnerability CVSS: 2.1 12 Feb 2001, 05:00 UTC

Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.

CVE-2001-0105 hp vulnerability CVSS: 2.1 12 Feb 2001, 05:00 UTC

Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.

CVE-2000-1126 hp vulnerability CVSS: 10.0 09 Jan 2001, 05:00 UTC

Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.

CVE-2000-1134 hp vulnerability CVSS: 7.2 09 Jan 2001, 05:00 UTC

Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

CVE-2000-1127 hp vulnerability CVSS: 3.6 09 Jan 2001, 05:00 UTC

registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.

CVE-1999-0307 hp vulnerability CVSS: 7.2 20 Dec 2000, 05:00 UTC

Buffer overflow in HP-UX cstm program allows local users to gain root privileges.

CVE-2000-0965 hp vulnerability CVSS: 5.0 19 Dec 2000, 05:00 UTC

The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).

CVE-2000-0966 hp vulnerability CVSS: 4.6 19 Dec 2000, 05:00 UTC

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

CVE-2000-0972 hp vulnerability CVSS: 2.1 19 Dec 2000, 05:00 UTC

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

CVE-2000-1028 hp vulnerability CVSS: 7.2 11 Dec 2000, 05:00 UTC

Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

CVE-2000-1058 hp vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem."

CVE-2000-1062 hp vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

CVE-2000-1063 hp vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

CVE-2000-1064 hp vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

CVE-2000-1065 hp vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.

CVE-2000-1031 hp vulnerability CVSS: 4.6 11 Dec 2000, 05:00 UTC

Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.

CVE-2000-1057 hp vulnerability CVSS: 4.6 11 Dec 2000, 05:00 UTC

Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.

CVE-2000-0699 hp vulnerability CVSS: 10.0 20 Oct 2000, 04:00 UTC

Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.

CVE-2000-0702 hp vulnerability CVSS: 7.2 20 Oct 2000, 04:00 UTC

The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.

CVE-2000-0801 hp vulnerability CVSS: 7.2 20 Oct 2000, 04:00 UTC

Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.

CVE-2000-0730 hp vulnerability CVSS: 4.6 20 Oct 2000, 04:00 UTC

Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.

CVE-2000-0755 hp vulnerability CVSS: 4.6 20 Oct 2000, 04:00 UTC

Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.

CVE-2000-0754 hp vulnerability CVSS: 2.1 20 Oct 2000, 04:00 UTC

Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.

CVE-2000-0636 hp vulnerability CVSS: 5.0 19 Jul 2000, 04:00 UTC

HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.

CVE-2000-0573 hp vulnerability CVSS: 10.0 07 Jul 2000, 04:00 UTC

The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.

CVE-2000-0616 hp vulnerability CVSS: 4.6 26 Jun 2000, 04:00 UTC

Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.

CVE-2000-0515 hp vulnerability CVSS: 10.0 07 Jun 2000, 04:00 UTC

The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.

CVE-2000-0558 hp vulnerability CVSS: 10.0 06 Jun 2000, 04:00 UTC

Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.

CVE-2000-0468 hp vulnerability CVSS: 4.6 02 Jun 2000, 04:00 UTC

man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.

CVE-2000-0443 hp vulnerability CVSS: 7.5 24 May 2000, 04:00 UTC

The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVE-2000-0444 hp vulnerability CVSS: 5.0 24 May 2000, 04:00 UTC

HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.

CVE-2000-0414 hp vulnerability CVSS: 4.6 04 May 2000, 04:00 UTC

Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.

CVE-2000-0083 hp vulnerability CVSS: 4.6 18 Apr 2000, 04:00 UTC

HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.

CVE-2000-0251 hp vulnerability CVSS: 5.0 06 Apr 2000, 04:00 UTC

HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.

CVE-1999-0693 hp vulnerability CVSS: 7.2 02 Mar 2000, 05:00 UTC

Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

CVE-2000-0179 hp vulnerability CVSS: 5.0 28 Feb 2000, 05:00 UTC

HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.

CVE-2000-0159 hp vulnerability CVSS: 7.5 17 Feb 2000, 05:00 UTC

HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.

CVE-2000-0095 hp vulnerability CVSS: 5.0 24 Jan 2000, 05:00 UTC

The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.

CVE-1999-0992 hp vulnerability CVSS: 10.0 18 Jan 2000, 05:00 UTC

HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).

CVE-2000-0077 hp vulnerability CVSS: 7.2 02 Jan 2000, 05:00 UTC

The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

CVE-2000-0078 hp vulnerability CVSS: 7.2 02 Jan 2000, 05:00 UTC

The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.

CVE-1999-1324 hp vulnerability CVSS: 7.5 31 Dec 1999, 05:00 UTC

VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.

CVE-1999-1573 hp vulnerability CVSS: 10.0 28 Dec 1999, 05:00 UTC

Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

CVE-1999-1163 hp vulnerability CVSS: 7.5 24 Nov 1999, 05:00 UTC

Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.

CVE-1999-0829 hp vulnerability CVSS: 5.0 01 Nov 1999, 05:00 UTC

HP Secure Web Console uses weak encryption.

CVE-1999-0696 hp vulnerability CVSS: 10.0 01 Jul 1999, 04:00 UTC

Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).

CVE-1999-0707 hp vulnerability CVSS: 7.5 01 Jul 1999, 04:00 UTC

The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.

CVE-1999-0690 hp vulnerability CVSS: 7.2 01 Jul 1999, 04:00 UTC

HP CDE program includes the current directory in root's PATH variable.

CVE-1999-0688 hp vulnerability CVSS: 4.6 01 Jul 1999, 04:00 UTC

Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.

CVE-1999-0686 hp vulnerability CVSS: 5.0 07 May 1999, 04:00 UTC

Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.

CVE-1999-0684 hp vulnerability CVSS: 5.0 19 Apr 1999, 04:00 UTC

Denial of service in Sendmail 8.8.6 in HPUX.

CVE-1999-0447 hp vulnerability CVSS: 4.6 01 Apr 1999, 05:00 UTC

Local users can gain privileges using the debug utility in the MPE/iX operating system.

CVE-1999-0435 hp vulnerability CVSS: 7.2 01 Mar 1999, 05:00 UTC

MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.

CVE-1999-0479 hp vulnerability CVSS: 5.0 01 Mar 1999, 05:00 UTC

Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.

CVE-1999-0432 hp vulnerability CVSS: 4.6 01 Mar 1999, 05:00 UTC

ftp on HP-UX 11.00 allows local users to gain privileges.

CVE-1999-0436 hp vulnerability CVSS: 4.6 01 Mar 1999, 05:00 UTC

Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.

CVE-1999-1247 hp vulnerability CVSS: 7.2 24 Feb 1999, 05:00 UTC

Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.

CVE-1999-0353 hp vulnerability CVSS: 9.3 10 Feb 1999, 05:00 UTC

rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

CVE-2000-0005 hp vulnerability CVSS: 7.2 02 Jan 1999, 05:00 UTC

HP-UX aserver program allows local users to gain privileges via a symlink attack.

CVE-1999-0057 hp vulnerability CVSS: 7.5 16 Nov 1998, 05:00 UTC

Vacation program allows command execution by remote users through a sendmail command.

CVE-1999-0779 hp vulnerability CVSS: 5.0 03 Sep 1998, 04:00 UTC

Denial of service in HP-UX SharedX recserv program.

CVE-1999-0333 hp vulnerability CVSS: 7.5 01 Aug 1998, 04:00 UTC

HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.

CVE-1999-1136 hp vulnerability CVSS: 4.6 30 Jul 1998, 04:00 UTC

Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.

CVE-1999-1433 hp vulnerability CVSS: 7.2 15 Jul 1998, 04:00 UTC

HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.

CVE-1999-0007 hp vulnerability CVSS: 5.0 26 Jun 1998, 04:00 UTC

Information from SSL-encrypted sessions via PKCS #1.

CVE-1999-0008 hp vulnerability CVSS: 10.0 08 Jun 1998, 04:00 UTC

Buffer overflow in NIS+, in Sun's rpc.nisd program.

CVE-1999-0003 hp vulnerability CVSS: 10.0 01 Apr 1998, 05:00 UTC

Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

CVE-1999-0551 hp vulnerability CVSS: 4.6 01 Apr 1998, 05:00 UTC

HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.

CVE-1999-0502 hp vulnerability CVSS: 7.5 01 Mar 1998, 05:00 UTC

A Unix account has a default, null, blank, or missing password.

CVE-1999-0014 hp vulnerability CVSS: 7.2 21 Jan 1998, 05:00 UTC

Unauthorized privileged access or denial of service via dtappgather program in CDE.

CVE-1999-0513 hp vulnerability CVSS: 5.0 05 Jan 1998, 05:00 UTC

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVE-1999-0004 hp vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.

CVE-1999-0015 hp vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

Teardrop IP denial of service.

CVE-1999-0104 hp vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.

CVE-1999-0016 hp vulnerability CVSS: 5.0 01 Dec 1997, 05:00 UTC

Land IP denial of service.

CVE-1999-0306 hp vulnerability CVSS: 7.2 04 Nov 1997, 05:00 UTC

buffer overflow in HP xlock program.

CVE-1999-0216 hp vulnerability CVSS: 5.0 01 Nov 1997, 05:00 UTC

Denial of service of inetd on Linux through SYN and RST packets.

CVE-1999-0097 hp vulnerability CVSS: 10.0 29 Oct 1997, 05:00 UTC

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

CVE-1999-1061 hp vulnerability CVSS: 7.5 04 Oct 1997, 04:00 UTC

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.

CVE-1999-1062 hp vulnerability CVSS: 7.5 04 Oct 1997, 04:00 UTC

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.

CVE-1999-1213 hp vulnerability CVSS: 5.0 01 Oct 1997, 04:00 UTC

Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.

CVE-1999-0326 hp vulnerability CVSS: 4.6 01 Oct 1997, 04:00 UTC

Vulnerability in HP-UX mediainit program.

CVE-1999-1139 hp vulnerability CVSS: 7.2 01 Sep 1997, 04:00 UTC

Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.

CVE-1999-1133 hp vulnerability CVSS: 4.6 01 Sep 1997, 04:00 UTC

HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.

CVE-1999-0524 hp vulnerability CVSS: 2.1 01 Aug 1997, 04:00 UTC

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

CVE-1999-1308 hp vulnerability CVSS: 4.6 31 Jul 1997, 04:00 UTC

Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.

CVE-1999-0962 hp vulnerability CVSS: 7.2 14 May 1997, 04:00 UTC

Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.

CVE-1999-0040 hp vulnerability CVSS: 7.2 01 May 1997, 04:00 UTC

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

CVE-1999-0038 hp vulnerability CVSS: 7.2 26 Apr 1997, 04:00 UTC

Buffer overflow in xlock program allows local users to execute commands as root.

CVE-1999-1408 hp vulnerability CVSS: 2.1 05 Mar 1997, 05:00 UTC

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVE-1999-0318 hp vulnerability CVSS: 7.2 01 Mar 1997, 05:00 UTC

Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

CVE-1999-0046 hp vulnerability CVSS: 10.0 06 Feb 1997, 05:00 UTC

Buffer overflow of rlogin program using TERM environmental variable.

CVE-1999-1160 hp vulnerability CVSS: 10.0 02 Feb 1997, 05:00 UTC

Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.

CVE-1999-0309 hp vulnerability CVSS: 7.2 01 Feb 1997, 05:00 UTC

HP-UX vgdisplay program gives root access to local users.

CVE-1999-1144 hp vulnerability CVSS: 7.2 30 Jan 1997, 05:00 UTC

Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.

CVE-1999-1088 hp vulnerability CVSS: 7.2 09 Jan 1997, 05:00 UTC

Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.

CVE-1999-1145 hp vulnerability CVSS: 7.2 07 Jan 1997, 05:00 UTC

Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.

CVE-1999-1311 hp vulnerability CVSS: 4.6 07 Jan 1997, 05:00 UTC

Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.

CVE-1999-1249 hp vulnerability CVSS: 4.6 06 Jan 1997, 05:00 UTC

movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.

CVE-1999-0517 hp vulnerability CVSS: 7.5 01 Jan 1997, 05:00 UTC

An SNMP community name is the default (e.g. public), null, or missing.

CVE-1999-1251 hp vulnerability CVSS: 2.1 24 Dec 1996, 05:00 UTC

Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.

CVE-1999-0127 hp vulnerability CVSS: 7.2 19 Dec 1996, 05:00 UTC

swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.

CVE-1999-1089 hp vulnerability CVSS: 7.2 13 Dec 1996, 05:00 UTC

Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.

CVE-1999-0129 hp vulnerability CVSS: 4.6 03 Dec 1996, 05:00 UTC

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

CVE-1999-0050 hp vulnerability CVSS: 7.2 01 Dec 1996, 05:00 UTC

Buffer overflow in HP-UX newgrp program.

CVE-1999-0130 hp vulnerability CVSS: 7.2 16 Nov 1996, 05:00 UTC

Local users can start Sendmail in daemon mode and gain root privileges.

CVE-1999-1161 hp vulnerability CVSS: 7.2 03 Nov 1996, 05:00 UTC

Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

CVE-1999-0311 hp vulnerability CVSS: 7.2 01 Nov 1996, 05:00 UTC

fpkg2swpk in HP-UX allows local users to gain root access.

CVE-1999-0336 hp vulnerability CVSS: 7.2 01 Nov 1996, 05:00 UTC

Buffer overflow in mstm in HP-UX allows local users to gain root access.

CVE-1999-0246 hp vulnerability CVSS: 10.0 01 Oct 1996, 04:00 UTC

HP Remote Watch allows a remote user to gain root access.

CVE-1999-0308 hp vulnerability CVSS: 4.6 01 Oct 1996, 04:00 UTC

HP-UX gwind program allows users to modify arbitrary files.

CVE-1999-0961 hp vulnerability CVSS: 6.2 21 Sep 1996, 04:00 UTC

HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

CVE-1999-0131 hp vulnerability CVSS: 7.2 11 Sep 1996, 04:00 UTC

Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

CVE-1999-0324 hp vulnerability CVSS: 7.2 01 Sep 1996, 04:00 UTC

ppl program in HP-UX allows local users to create root files through symlinks.

CVE-1999-0132 hp vulnerability CVSS: 2.1 15 Aug 1996, 04:00 UTC

Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.

CVE-1999-0022 hp vulnerability CVSS: 7.2 03 Jul 1996, 04:00 UTC

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

CVE-1999-0138 hp vulnerability CVSS: 7.2 26 Jun 1996, 04:00 UTC

The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

CVE-1999-1205 hp vulnerability CVSS: 2.1 07 Jun 1996, 04:00 UTC

nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.

CVE-1999-0078 hp vulnerability CVSS: 1.9 18 Apr 1996, 04:00 UTC

pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

CVE-1999-0325 hp vulnerability CVSS: 7.2 01 Dec 1995, 05:00 UTC

vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.

CVE-1999-1248 hp vulnerability CVSS: 4.6 30 Nov 1994, 05:00 UTC

Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.

CVE-1999-1238 hp vulnerability CVSS: 4.6 21 Sep 1994, 04:00 UTC

Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.

CVE-1999-1239 hp vulnerability CVSS: 4.6 13 Jul 1994, 04:00 UTC

HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.

CVE-1999-0423 hp vulnerability CVSS: 4.6 01 Jun 1994, 04:00 UTC

Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.

CVE-1999-1134 hp vulnerability CVSS: 7.2 18 May 1994, 04:00 UTC

Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.

CVE-1999-1146 hp vulnerability CVSS: 7.2 04 May 1994, 04:00 UTC

Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.

CVE-1999-1135 hp vulnerability CVSS: 7.2 20 Apr 1994, 04:00 UTC

Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.

CVE-1999-1242 hp vulnerability CVSS: 4.6 07 Feb 1994, 05:00 UTC

Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.

CVE-1999-0312 hp vulnerability CVSS: 5.0 13 Jan 1993, 05:00 UTC

HP ypbind allows attackers with root privileges to modify NIS data.

CVE-1999-1493 hp vulnerability CVSS: 10.0 18 Dec 1991, 05:00 UTC

Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().

CVE-1999-1115 hp vulnerability CVSS: 7.2 31 Dec 1990, 05:00 UTC

Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).