Lucene search

K

Hp Security Vulnerabilities

cve
cve

CVE-2019-5392

A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

5.3CVSS

5AI Score

0.005EPSS

2019-06-05 03:29 PM
91
cve
cve

CVE-2019-5393

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

4.3CVSS

5.3AI Score

0.001EPSS

2019-06-05 03:29 PM
28
cve
cve

CVE-2019-5394

The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

5.1CVSS

5.1AI Score

0.0004EPSS

2019-06-05 06:29 PM
42
cve
cve

CVE-2019-5395

A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

8.8CVSS

8.6AI Score

0.004EPSS

2019-08-09 05:15 PM
37
cve
cve

CVE-2019-5396

A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

9.4CVSS

9.3AI Score

0.003EPSS

2019-08-09 05:15 PM
30
cve
cve

CVE-2019-5397

A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

9.4CVSS

9.1AI Score

0.002EPSS

2019-08-09 06:15 PM
65
cve
cve

CVE-2019-5398

A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

5.4CVSS

5.4AI Score

0.001EPSS

2019-08-09 06:15 PM
46
cve
cve

CVE-2019-5399

A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

9.4CVSS

9.2AI Score

0.001EPSS

2019-08-09 06:15 PM
68
cve
cve

CVE-2019-5400

A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

6.3CVSS

6.3AI Score

0.001EPSS

2019-08-09 06:15 PM
50
cve
cve

CVE-2019-5401

A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure the...

4.8CVSS

5.4AI Score

0.001EPSS

2019-08-01 10:15 PM
59
cve
cve

CVE-2019-5402

A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

9.4CVSS

9.1AI Score

0.003EPSS

2019-08-09 06:15 PM
68
cve
cve

CVE-2019-5403

A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

4.8CVSS

4.9AI Score

0.001EPSS

2019-08-09 06:15 PM
50
cve
cve

CVE-2019-5404

A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

8.8CVSS

8.6AI Score

0.001EPSS

2019-08-09 06:15 PM
60
cve
cve

CVE-2019-5405

A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

7.3CVSS

7.1AI Score

0.001EPSS

2019-08-09 06:15 PM
63
cve
cve

CVE-2019-5406

A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

7.2CVSS

6.9AI Score

0.001EPSS

2019-08-09 06:15 PM
52
cve
cve

CVE-2019-5407

A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

6.3CVSS

6.1AI Score

0.001EPSS

2019-08-09 06:15 PM
48
cve
cve

CVE-2019-5408

Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version...

6.5CVSS

6.4AI Score

0.001EPSS

2019-08-09 06:15 PM
47
cve
cve

CVE-2019-5736

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attack...

8.6CVSS

8.8AI Score

0.004EPSS

2019-02-11 07:29 PM
493
In Wild
9
cve
cve

CVE-2019-6318

HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.

9.8CVSS

9.6AI Score

0.003EPSS

2019-04-11 03:29 PM
34
cve
cve

CVE-2019-6319

HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

8.1CVSS

8AI Score

0.001EPSS

2020-01-09 08:15 PM
32
cve
cve

CVE-2019-6320

Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

8.1CVSS

8AI Score

0.001EPSS

2020-01-09 07:15 PM
28
cve
cve

CVE-2019-6321

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default.

7.2CVSS

6.9AI Score

0.001EPSS

2019-05-29 08:29 PM
127
cve
cve

CVE-2019-6322

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default.

6.8CVSS

6.7AI Score

0.001EPSS

2019-05-29 08:29 PM
129
cve
cve

CVE-2019-6323

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page.

6.1CVSS

6.5AI Score

0.001EPSS

2019-06-17 04:15 PM
36
cve
cve

CVE-2019-6324

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in wireless configuration page

4.8CVSS

5.7AI Score

0.001EPSS

2019-06-17 04:15 PM
39
cve
cve

CVE-2019-6325

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery.

8.8CVSS

8.9AI Score

0.001EPSS

2019-06-17 04:15 PM
36
cve
cve

CVE-2019-6326

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow.

7.2CVSS

7.5AI Score

0.001EPSS

2019-06-17 04:15 PM
38
cve
cve

CVE-2019-6327

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an IPP Parser potentially vulnerable to Buffer Overflow.

9.8CVSS

9.4AI Score

0.002EPSS

2019-06-17 04:15 PM
52
cve
cve

CVE-2019-6328

HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.

7.8CVSS

7.6AI Score

0.0004EPSS

2019-06-25 05:15 PM
140
cve
cve

CVE-2019-6329

HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.

7.8CVSS

7.6AI Score

0.0004EPSS

2019-06-25 05:15 PM
128
cve
cve

CVE-2019-6330

A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

9.8CVSS

9.3AI Score

0.002EPSS

2020-01-09 07:15 PM
23
cve
cve

CVE-2019-6331

An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.

3.3CVSS

4.2AI Score

0.0004EPSS

2020-01-09 07:15 PM
22
cve
cve

CVE-2019-6332

A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A;...

4.8CVSS

4.9AI Score

0.001EPSS

2020-01-09 07:15 PM
40
cve
cve

CVE-2019-6333

A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system service.

6.7CVSS

7AI Score

0.0004EPSS

2019-10-11 05:15 PM
75
cve
cve

CVE-2019-6334

HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.

9.8CVSS

9.5AI Score

0.003EPSS

2019-10-16 03:15 PM
45
cve
cve

CVE-2019-6335

A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially be exploited to create a denial of service.

7.5CVSS

7.4AI Score

0.001EPSS

2019-10-11 06:15 PM
60
cve
cve

CVE-2019-6337

For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

5.2CVSS

6.9AI Score

0.001EPSS

2019-11-07 03:15 PM
24
cve
cve

CVE-2019-7317

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

5.3CVSS

6.3AI Score

0.005EPSS

2019-02-04 08:29 AM
487
cve
cve

CVE-2020-10136

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.

5.3CVSS

5.2AI Score

0.015EPSS

2020-06-02 09:15 AM
104
4
cve
cve

CVE-2020-11853

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 w...

8.8CVSS

8.8AI Score

0.837EPSS

2020-10-22 09:15 PM
101
4
cve
cve

CVE-2020-12695

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

7.5CVSS

7.6AI Score

0.005EPSS

2020-06-08 05:15 PM
478
3
cve
cve

CVE-2020-15596

The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

6.7CVSS

6.3AI Score

0.0004EPSS

2020-08-12 10:15 PM
26
cve
cve

CVE-2020-24629

A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.5AI Score

0.004EPSS

2020-10-19 06:15 PM
46
cve
cve

CVE-2020-24630

A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

8.8AI Score

0.003EPSS

2020-10-19 06:15 PM
52
cve
cve

CVE-2020-24646

A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.9AI Score

0.011EPSS

2020-10-19 06:15 PM
30
cve
cve

CVE-2020-24647

A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.5AI Score

0.005EPSS

2020-10-19 06:15 PM
21
cve
cve

CVE-2020-24648

A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.7AI Score

0.03EPSS

2020-10-19 06:15 PM
27
cve
cve

CVE-2020-24649

A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.5AI Score

0.005EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-24650

A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.8AI Score

0.006EPSS

2020-10-19 06:15 PM
20
cve
cve

CVE-2020-24651

A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

9.8CVSS

9.8AI Score

0.006EPSS

2020-10-19 06:15 PM
42
Total number of security vulnerabilities2181