Lucene search

K

Hp Security Vulnerabilities

cve
cve

CVE-2011-1732

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed stutil message.

8.2AI Score

0.854EPSS

2011-05-07 07:55 PM
24
cve
cve

CVE-2011-1733

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed HPFGConfig message.

8.2AI Score

0.854EPSS

2011-05-07 07:55 PM
25
cve
cve

CVE-2011-1734

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed omniiaputil message.

8.2AI Score

0.871EPSS

2011-05-07 07:55 PM
28
cve
cve

CVE-2011-1735

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed bm message.

8.2AI Score

0.816EPSS

2011-05-07 07:55 PM
28
cve
cve

CVE-2011-1736

Directory traversal vulnerability in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to read arbitrary files via directory traversal sequences in a filename in a GET_FILE message.

6.7AI Score

0.051EPSS

2011-05-07 07:55 PM
27
cve
cve

CVE-2011-1737

Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.014EPSS

2011-05-13 05:05 PM
20
cve
cve

CVE-2011-1738

HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.

6.8AI Score

0.0004EPSS

2011-05-13 05:05 PM
23
cve
cve

CVE-2011-1848

Stack-based buffer overflow in img.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a crafted length field in a packet.

7.9AI Score

0.122EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2011-1849

tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to create or overwrite files, and subsequently execute arbitrary code, via a crafted WRQ request.

7.1AI Score

0.089EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2011-1850

Stack-based buffer overflow in the logging functionality in dbman.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via vectors related to a received action.

8AI Score

0.12EPSS

2022-10-03 04:15 PM
34
cve
cve

CVE-2011-1851

Stack-based buffer overflow in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long mode field.

8AI Score

0.12EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2011-1852

Multiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execute arbitrary code via crafted packet content accompanying a (1) DATA or (2) ERROR opcode.

7.7AI Score

0.139EPSS

2022-10-03 04:15 PM
30
cve
cve

CVE-2011-1853

tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2) invalid opcode field, related to a function pointer table.

7.6AI Score

0.114EPSS

2022-10-03 04:15 PM
26
cve
cve

CVE-2011-1854

Use-after-free vulnerability in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long syslog packet, related to an exception handler.

7.6AI Score

0.092EPSS

2022-10-03 04:15 PM
25
cve
cve

CVE-2011-1855

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors.

6.2AI Score

0.0004EPSS

2011-05-13 05:05 PM
18
cve
cve

CVE-2011-1856

Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.06 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6AI Score

0.014EPSS

2011-05-16 06:55 PM
24
cve
cve

CVE-2011-1857

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

6.3AI Score

0.006EPSS

2011-06-14 05:55 PM
25
cve
cve

CVE-2011-1858

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors.

6.4AI Score

0.0004EPSS

2011-06-14 05:55 PM
22
cve
cve

CVE-2011-1859

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors.

6.3AI Score

0.005EPSS

2011-06-14 05:55 PM
28
cve
cve

CVE-2011-1860

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors.

6.8AI Score

0.005EPSS

2011-06-14 05:55 PM
23
cve
cve

CVE-2011-1861

Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.

6.4AI Score

0.023EPSS

2011-06-14 05:55 PM
21
cve
cve

CVE-2011-1862

Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.002EPSS

2011-06-14 05:55 PM
23
cve
cve

CVE-2011-1863

HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors.

6.7AI Score

0.006EPSS

2011-06-14 05:55 PM
30
cve
cve

CVE-2011-1864

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors.

7.6AI Score

0.6EPSS

2011-06-14 05:55 PM
31
cve
cve

CVE-2011-1865

Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.

7.6AI Score

0.955EPSS

2011-07-01 10:55 AM
23
cve
cve

CVE-2011-1866

Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.

7.7AI Score

0.872EPSS

2011-07-01 10:55 AM
28
cve
cve

CVE-2011-1867

Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via...

8AI Score

0.854EPSS

2011-07-11 08:55 PM
24
cve
cve

CVE-2011-2328

Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives.

8.4AI Score

0.069EPSS

2011-06-02 08:55 PM
26
cve
cve

CVE-2011-2331

Integer overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in an a packet that triggers a heap-based buffer overflow, possibly related to an "recv" field.

8.3AI Score

0.174EPSS

2011-06-02 08:55 PM
15
cve
cve

CVE-2011-2398

Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges or cause a denial of service via unknown vectors.

6.5AI Score

0.0004EPSS

2011-07-11 08:55 PM
29
cve
cve

CVE-2011-2399

Unspecified vulnerability in the Media Management Daemon (mmd) in HP Data Protector 6.11 and earlier allows remote attackers to cause a denial of service via unknown vectors.

6.6AI Score

0.022EPSS

2011-08-01 07:55 PM
32
cve
cve

CVE-2011-2400

Cross-site scripting (XSS) vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.002EPSS

2011-07-29 08:55 PM
18
cve
cve

CVE-2011-2401

Session fixation vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to hijack web sessions via unspecified vectors.

6.7AI Score

0.016EPSS

2011-07-29 08:55 PM
21
cve
cve

CVE-2011-2402

Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.002EPSS

2011-08-01 07:55 PM
23
cve
cve

CVE-2011-2403

SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

8.2AI Score

0.003EPSS

2011-08-01 07:55 PM
23
cve
cve

CVE-2011-2404

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787.

6.8AI Score

0.933EPSS

2011-08-11 10:55 PM
32
cve
cve

CVE-2011-2405

The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.

6.9AI Score

0.007EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2011-2406

Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

5.3AI Score

0.002EPSS

2011-08-11 10:55 PM
18
cve
cve

CVE-2011-2407

Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors.

6.6AI Score

0.002EPSS

2011-08-11 10:55 PM
17
cve
cve

CVE-2011-2408

Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.007EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2011-2409

Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.007EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2011-2410

Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.002EPSS

2022-10-03 04:15 PM
18
cve
cve

CVE-2011-2411

Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.

7.6AI Score

0.005EPSS

2022-10-03 04:15 PM
25
cve
cve

CVE-2011-2412

Unspecified vulnerability in HP Business Service Automation (BSA) Essentials 2.01 allows remote attackers to execute arbitrary code via unknown vectors.

7.9AI Score

0.113EPSS

2011-09-21 04:55 PM
18
cve
cve

CVE-2011-2608

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

6.9AI Score

0.031EPSS

2011-07-01 10:55 AM
23
cve
cve

CVE-2011-2697

foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.

5.8AI Score

0.045EPSS

2011-07-29 08:55 PM
34
cve
cve

CVE-2011-2722

The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.

5.9AI Score

0.0004EPSS

2012-05-25 08:55 PM
31
cve
cve

CVE-2011-2779

Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.

6.4AI Score

0.018EPSS

2011-07-19 09:55 PM
20
cve
cve

CVE-2011-3155

Unspecified vulnerability in HP Onboard Administrator (OA) 3.21 through 3.31 allows remote attackers to bypass intended access restrictions via unknown vectors.

6.8AI Score

0.003EPSS

2011-10-12 02:52 AM
26
cve
cve

CVE-2011-3156

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222.

7.8AI Score

0.932EPSS

2011-10-19 03:55 PM
99
Total number of security vulnerabilities2180