Total
75 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4396 | 1 Hp | 1 System Management Homepage | 2017-02-16 | 7.8 HIGH | 7.5 HIGH |
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue. | |||||
CVE-2016-4395 | 1 Hp | 1 System Management Homepage | 2017-02-16 | 7.8 HIGH | 7.5 HIGH |
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue. | |||||
CVE-2016-4394 | 1 Hp | 1 System Management Homepage | 2017-02-16 | 5.8 MEDIUM | 6.5 MEDIUM |
HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue. | |||||
CVE-2016-4393 | 1 Hp | 1 System Management Homepage | 2017-02-16 | 3.5 LOW | 5.4 MEDIUM |
HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue. | |||||
CVE-2016-1993 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 5.5 MEDIUM | 8.1 HIGH |
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-1996 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 3.6 LOW | 7.7 HIGH |
HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-1995 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2016-1994 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-2015 | 1 Hp | 1 System Management Homepage | 2016-11-30 | 6.6 MEDIUM | 7.1 HIGH |
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2013-3576 | 1 Hp | 1 System Management Homepage | 2014-01-07 | 9.0 HIGH | N/A |
ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en. | |||||
CVE-2011-3846 | 1 Hp | 1 System Management Homepage | 2012-04-12 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts. | |||||
CVE-2011-1541 | 1 Hp | 1 System Management Homepage | 2011-09-21 | 10.0 HIGH | N/A |
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and consequently execute arbitrary code, via unknown vectors. | |||||
CVE-2011-1540 | 1 Hp | 1 System Management Homepage | 2011-09-21 | 9.0 HIGH | N/A |
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authenticated users to execute arbitrary code via unknown vectors. | |||||
CVE-2008-1663 | 1 Hp | 1 System Management Homepage | 2011-03-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2007-4931 | 1 Hp | 1 System Management Homepage | 2011-03-07 | 2.1 LOW | N/A |
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL. |