Filtered by vendor Hp
Subscribe
Total
2279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-6860 | 1 Hp | 54 J8692a, J8693a, J8697a and 51 more | 2016-12-07 | 7.2 HIGH | 8.4 HIGH |
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859. | |||||
CVE-2015-6862 | 1 Hp | 1 Ucmdb Browser | 2016-12-07 | 7.2 HIGH | 8.4 HIGH |
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. | |||||
CVE-2015-6859 | 1 Hp | 54 J8692a, J8693a, J8697a and 51 more | 2016-12-07 | 4.6 MEDIUM | 7.8 HIGH |
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860. | |||||
CVE-2015-5446 | 1 Hp | 1 Storeonce Backup System Software | 2016-12-07 | 5.8 MEDIUM | 7.5 HIGH |
HP StoreOnce Backup system software before 3.13.1 allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2015-5445 | 1 Hp | 1 Storeonce Backup System Software | 2016-12-07 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |||||
CVE-2015-5447 | 1 Hp | 1 Storeonce Backup System Software | 2016-12-07 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-5451 | 1 Hp | 1 Operations Orchestration | 2016-12-07 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||||
CVE-2015-2902 | 1 Hp | 1 Arcsight Smartconnectors | 2016-12-07 | 6.8 MEDIUM | N/A |
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate. | |||||
CVE-2015-2903 | 1 Hp | 1 Arcsight Smartconnectors | 2016-12-07 | 6.9 MEDIUM | N/A |
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password. | |||||
CVE-2016-1987 | 1 Hp | 1 Hp-ux Ipfilter | 2016-12-05 | 2.6 LOW | 5.9 MEDIUM |
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets. | |||||
CVE-2016-1993 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 5.5 MEDIUM | 8.1 HIGH |
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-2244 | 1 Hp | 55 A2w75a, A2w76a, A2w77a and 52 more | 2016-12-02 | 5.0 MEDIUM | 5.9 MEDIUM |
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-2243 | 1 Hp | 30 1000 Series Firmware, 700 Series Firmware, 800 Series Firmware and 27 more | 2016-12-02 | 5.4 MEDIUM | 7.9 HIGH |
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access. | |||||
CVE-2016-2001 | 1 Hp | 1 Universal Cmbd Foundation | 2016-12-02 | 5.8 MEDIUM | 7.4 HIGH |
HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection attacks via unspecified vectors. | |||||
CVE-2016-1988 | 1 Hp | 1 Network Automation | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989. | |||||
CVE-2016-1989 | 1 Hp | 1 Network Automation | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988. | |||||
CVE-2016-1996 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 3.6 LOW | 7.7 HIGH |
HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-1995 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2016-1992 | 1 Hp | 2 Enterprise Security Manager, Enterprise Security Manager Express | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1994 | 1 Hp | 1 System Management Homepage | 2016-12-02 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. |