Lucene search

K

Hp Security Vulnerabilities

cve
cve

CVE-2014-2600

Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.

6.4AI Score

0.002EPSS

2014-04-05 02:55 PM
23
cve
cve

CVE-2014-2601

The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

7.5AI Score

0.972EPSS

2014-04-24 11:55 PM
56
In Wild
cve
cve

CVE-2014-2602

Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors.

6.6AI Score

0.002EPSS

2014-05-08 10:55 AM
19
cve
cve

CVE-2014-2603

Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.

6AI Score

0.001EPSS

2014-05-10 01:55 AM
20
cve
cve

CVE-2014-2604

Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.

6.8AI Score

0.007EPSS

2014-05-22 11:14 AM
28
cve
cve

CVE-2014-2605

Unspecified vulnerability in HP StoreVirtual 4000 Storage and StoreVirtual VSA 9.5 through 11.0 allows remote attackers to obtain sensitive information via unknown vectors.

6.3AI Score

0.003EPSS

2014-07-16 04:58 AM
25
cve
cve

CVE-2014-2606

Unspecified vulnerability in HP StoreVirtual 4000 Storage and StoreVirtual VSA 9.5 through 11.0 allows remote authenticated users to gain privileges via unknown vectors.

6.6AI Score

0.004EPSS

2014-07-16 04:58 AM
25
cve
cve

CVE-2014-2607

Unspecified vulnerability in HP Operations Manager i 9.1 through 9.13 and 9.2 through 9.24 allows remote authenticated users to execute arbitrary code by leveraging the OMi operator role.

7.5AI Score

0.004EPSS

2014-05-26 12:25 AM
22
cve
cve

CVE-2014-2609

The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.

7.9AI Score

0.572EPSS

2014-06-19 10:50 AM
35
cve
cve

CVE-2014-2610

Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117.

7.5AI Score

0.034EPSS

2014-06-19 10:50 AM
23
cve
cve

CVE-2014-2611

Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code, or obtain sensitive information or delete data, via unspecified vectors, aka ZDI-CAN-2120.

6.8AI Score

0.023EPSS

2014-06-19 10:50 AM
19
cve
cve

CVE-2014-2612

Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.

5.8AI Score

0.059EPSS

2014-06-28 03:55 PM
26
cve
cve

CVE-2014-2613

Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors.

6.6AI Score

0.004EPSS

2014-06-28 03:55 PM
18
cve
cve

CVE-2014-2614

Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-2140.

6.9AI Score

0.924EPSS

2014-07-07 11:01 AM
28
cve
cve

CVE-2014-2615

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2083.

7.5AI Score

0.179EPSS

2014-07-07 11:01 AM
22
cve
cve

CVE-2014-2616

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.

7.6AI Score

0.12EPSS

2014-07-07 11:01 AM
18
cve
cve

CVE-2014-2617

Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2104.

7.5AI Score

0.179EPSS

2014-07-07 11:01 AM
25
cve
cve

CVE-2014-2618

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2080.

6.2AI Score

0.919EPSS

2014-07-16 04:58 AM
35
cve
cve

CVE-2014-2619

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2088.

6.2AI Score

0.03EPSS

2014-07-16 04:58 AM
31
cve
cve

CVE-2014-2620

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2089.

6.2AI Score

0.03EPSS

2014-07-16 04:58 AM
34
cve
cve

CVE-2014-2621

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-2090.

6.2AI Score

0.03EPSS

2014-07-16 04:58 AM
27
cve
cve

CVE-2014-2622

Unspecified vulnerability in HP Intelligent Management Center (iMC) before 7.0 E02020P03 and Branch Intelligent Management System (BIMS) before 7.0 E0201P02 allows remote authenticated users to obtain sensitive information or modify data via unknown vectors, aka ZDI-CAN-2312.

5.8AI Score

0.008EPSS

2014-07-16 04:58 AM
26
cve
cve

CVE-2014-2623

Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

9.5AI Score

0.522EPSS

2014-07-18 01:00 AM
49
cve
cve

CVE-2014-2624

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.

7.5AI Score

0.971EPSS

2014-09-11 01:55 AM
58
cve
cve

CVE-2014-2625

Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023.

6.8AI Score

0.084EPSS

2014-07-26 03:55 PM
39
cve
cve

CVE-2014-2626

Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

7.3AI Score

0.86EPSS

2014-07-26 03:55 PM
54
cve
cve

CVE-2014-2627

Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

6.8AI Score

0.008EPSS

2014-08-01 05:12 AM
14
cve
cve

CVE-2014-2628

Unspecified vulnerability in HP Enterprise Maps 1 allows remote authenticated users to obtain sensitive information via unknown vectors.

5.8AI Score

0.001EPSS

2014-08-12 12:55 AM
22
cve
cve

CVE-2014-2629

HP NonStop Safeguard Security Software G, H06.03 through H06.28.01, and J06.03 through J06.17.01 does not properly evaluate the DISKFILE-PATTERN ACL of a program object file, which allows remote authenticated users to bypass intended restrictions on program access via vectors related to process-cre...

6.4AI Score

0.001EPSS

2014-08-12 02:55 PM
16
cve
cve

CVE-2014-2630

Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.

6.3AI Score

0.001EPSS

2014-08-12 05:01 AM
102
cve
cve

CVE-2014-2631

Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2138.

6.7AI Score

0.24EPSS

2014-08-12 12:55 AM
21
cve
cve

CVE-2014-2632

Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors.

7.9AI Score

0.104EPSS

2014-08-23 11:55 PM
18
cve
cve

CVE-2014-2633

Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

7.3AI Score

0.003EPSS

2014-08-23 11:55 PM
17
cve
cve

CVE-2014-2634

Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.

7.1AI Score

0.011EPSS

2014-08-23 11:55 PM
17
cve
cve

CVE-2014-2635

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2343.

7.7AI Score

0.913EPSS

2014-10-10 01:55 AM
19
cve
cve

CVE-2014-2636

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2336.

7.8AI Score

0.913EPSS

2014-10-10 01:55 AM
20
cve
cve

CVE-2014-2637

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2342.

7.8AI Score

0.913EPSS

2014-10-10 01:55 AM
24
cve
cve

CVE-2014-2638

Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2344.

7.7AI Score

0.913EPSS

2014-10-10 01:55 AM
23
cve
cve

CVE-2014-2639

Unspecified vulnerability in HP MPIO Device Specific Module Manager before 4.02.00 allows local users to gain privileges via unknown vectors.

6.6AI Score

0.0004EPSS

2014-09-28 07:55 PM
19
cve
cve

CVE-2014-2640

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.6AI Score

0.299EPSS

2014-10-02 12:55 AM
29
cve
cve

CVE-2014-2641

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

6.7AI Score

0.001EPSS

2014-10-02 12:55 AM
39
cve
cve

CVE-2014-2642

HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

6.7AI Score

0.011EPSS

2014-10-02 12:55 AM
38
cve
cve

CVE-2014-2643

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote authenticated users to gain privileges via unknown vectors.

6.6AI Score

0.004EPSS

2014-10-05 01:55 AM
24
cve
cve

CVE-2014-2644

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

5.7AI Score

0.054EPSS

2014-10-06 01:55 AM
24
cve
cve

CVE-2014-2645

HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.

6.8AI Score

0.011EPSS

2014-10-05 01:55 AM
27
cve
cve

CVE-2014-2646

Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.

6.4AI Score

0.0004EPSS

2014-10-10 01:55 AM
15
cve
cve

CVE-2014-2647

Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.6AI Score

0.002EPSS

2014-10-19 01:55 AM
51
cve
cve

CVE-2014-2648

Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.

7.8AI Score

0.045EPSS

2014-10-10 01:55 AM
179
cve
cve

CVE-2014-2649

Unspecified vulnerability in HP Operations Manager 9.20 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.

7.8AI Score

0.029EPSS

2014-10-10 01:55 AM
27
cve
cve

CVE-2014-3956

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

5.9AI Score

0.0004EPSS

2014-06-04 11:19 AM
209
Total number of security vulnerabilities2181