Vulnerabilities (CVE)

Filtered by vendor Hp Subscribe
Total 2415 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4371 1 Hp 6 Service Manager, Service Manager Mobility, Service Manager Server and 3 more 2016-12-16 6.0 MEDIUM 8.0 HIGH
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.
CVE-2015-5442 1 Hp 1 Software Update 2016-12-08 4.6 MEDIUM N/A
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.
CVE-2015-6862 1 Hp 1 Ucmdb Browser 2016-12-07 7.2 HIGH 8.4 HIGH
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.
CVE-2015-6860 1 Hp 54 J8692a, J8693a, J8697a and 51 more 2016-12-07 7.2 HIGH 8.4 HIGH
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.
CVE-2015-6859 1 Hp 54 J8692a, J8693a, J8697a and 51 more 2016-12-07 4.6 MEDIUM 7.8 HIGH
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860.
CVE-2015-6857 1 Hp 2 Loadrunner, Performance Center 2016-12-07 7.2 HIGH N/A
Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-3138.
CVE-2015-5451 1 Hp 1 Operations Orchestration 2016-12-07 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2015-5447 1 Hp 1 Storeonce Backup System Software 2016-12-07 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-5446 1 Hp 1 Storeonce Backup System Software 2016-12-07 5.8 MEDIUM 7.5 HIGH
HP StoreOnce Backup system software before 3.13.1 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-5445 1 Hp 1 Storeonce Backup System Software 2016-12-07 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVE-2015-2903 1 Hp 1 Arcsight Smartconnectors 2016-12-07 6.9 MEDIUM N/A
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.
CVE-2015-2902 1 Hp 1 Arcsight Smartconnectors 2016-12-07 6.8 MEDIUM N/A
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.
CVE-2016-1987 1 Hp 1 Hp-ux Ipfilter 2016-12-06 2.6 LOW 5.9 MEDIUM
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
CVE-2016-2244 1 Hp 55 A2w75a, A2w76a, A2w77a and 52 more 2016-12-03 5.0 MEDIUM 5.9 MEDIUM
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2016-2243 3 Hp, Samsung, Zyxel 30 1000 Series Firmware, 700 Series Firmware, 800 Series Firmware and 27 more 2016-12-03 5.4 MEDIUM 7.9 HIGH
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
CVE-2016-2001 1 Hp 1 Universal Cmbd Foundation 2016-12-03 5.8 MEDIUM 7.4 HIGH
HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection attacks via unspecified vectors.
CVE-2016-1996 1 Hp 1 System Management Homepage 2016-12-03 3.6 LOW 7.7 HIGH
HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.
CVE-2016-1995 1 Hp 1 System Management Homepage 2016-12-03 10.0 HIGH 9.8 CRITICAL
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2016-1994 1 Hp 1 System Management Homepage 2016-12-03 4.0 MEDIUM 6.5 MEDIUM
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVE-2016-1993 1 Hp 1 System Management Homepage 2016-12-03 5.5 MEDIUM 8.1 HIGH
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.