Записи HP
2 534 опубликованных записей вендора hp.
Профиль для исследователя
- Попали в KEV
- 6 · 0,2 %
- С эксплойтом
- 102 · 4 %
- Pre-auth RCE
- 539
- С записью об исправлении
- 7 %
- Медиана: публикация → KEV
- 2799 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')181
- CWE-20 Improper Input Validation160
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer134
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')116
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor106
- CWE-264 Permissions, Privileges, and Access Controls65
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 534 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
93Срочно | CVE-2013-4810Готовый эксплойт | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remhp · application lifecycle management · CWE-94 | Критическая9,8 | KEV | 79,5 % | 16 сент. 2013 г. |
91Срочно | CVE-2005-2773Готовый эксплойт | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) hp · openview network node manager · CWE-77 | Критическая9,8 | KEV | 74,6 % | 2 сент. 2005 г. |
85Срочно | CVE-2015-8651Готовый эксплойт | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | Высокая8,8 | KEV | 67,7 % | 28 дек. 2015 г. |
70На этой неделе | CVE-2017-12542Готовый эксплойт | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.hp · integrated lights-out 4 firmware | Критическая10,0 | — | 99,3 % | 15 февр. 2018 г. |
69На этой неделе | CVE-2020-7209Готовый эксплойт | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.hp · linuxki | Критическая9,8 | — | 98,8 % | 12 февр. 2020 г. |
69На этой неделе | CVE-2000-0573Готовый эксплойт | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exechp · hp-ux | Критическая10,0 | — | 96,2 % | 7 июл. 2000 г. |
68На этой неделе | CVE-2001-0797Готовый эксплойт | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Критическая10,0 | — | 94,7 % | 12 дек. 2001 г. |
67На этой неделе | CVE-2016-2004Готовый эксплойт | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vehp · data protector · CWE-306 | Критическая9,8 | — | 94,3 % | 21 апр. 2016 г. |
67На этой неделе | CVE-2014-2623Готовый эксплойт | Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.hp · storage data protector | Критическая10,0 | — | 90,7 % | 17 июл. 2014 г. |
67На этой неделе | CVE-2013-2333Готовый эксплойт | Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknhp · storage data protector | Критическая10,0 | — | 89,8 % | 6 июн. 2013 г. |
67На этой неделе | CVE-2011-1865Готовый эксплойт | Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to hp · openview storage data protector · CWE-119 | Критическая10,0 | — | 88,9 % | 1 июл. 2011 г. |
66На этой неделе | CVE-2003-0085Proof of concept | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alsamba · samba | Критическая10,0 | — | 86,4 % | 31 мар. 2003 г. |
65На этой неделе | CVE-2017-5816Готовый эксплойт | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Критическая9,8 | — | 86,2 % | 15 февр. 2018 г. |
65На этой неделе | CVE-2003-0201Готовый эксплойт | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Критическая10,0 | — | 84,5 % | 5 мая 2003 г. |
65На этой неделе | CVE-2011-0276Готовый эксплойт | HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager hp · openview performance insight | Критическая10,0 | — | 82,4 % | 1 февр. 2011 г. |
64На этой неделе | CVE-2019-5736Готовый эксплойт | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Высокая8,6 | — | 98,5 % | 11 февр. 2019 г. |
64На этой неделе | CVE-2017-2741Готовый эксплойт | A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.hp · j9v82a firmware | Критическая9,8 | — | 84,6 % | 23 янв. 2018 г. |
64На этой неделе | CVE-2017-5817Готовый эксплойт | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Критическая9,8 | — | 82,6 % | 15 февр. 2018 г. |
64На этой неделе | CVE-2020-7200Готовый эксплойт | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.hp · systems insight manager | Критическая9,8 | — | 81,9 % | 18 дек. 2020 г. |
64На этой неделе | CVE-2011-0923Готовый эксплойт | The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code hp · data protector · CWE-20 | Критическая10,0 | — | 81,1 % | 8 февр. 2011 г. |
64На этой неделе | CVE-2009-3843Готовый эксплойт | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Критическая10,0 | — | 79,0 % | 23 нояб. 2009 г. |
64На этой неделе | CVE-2009-4189Готовый эксплойт | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code hp · operations manager · CWE-255 | Критическая10,0 | — | 78,5 % | 3 дек. 2009 г. |
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2013-481093Срочно
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow rem
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 79 %hp · application lifecycle management16 сент. 2013 г.
- CVE-2005-277391Срочно
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %hp · openview network node manager2 сент. 2005 г.
- CVE-2015-865185Срочно
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 68 %adobe · air sdk28 дек. 2015 г.
- CVE-2017-1254270На этой неделе
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
КритическаяCVSS 10,0Готовый эксплойтEPSS 99 %hp · integrated lights-out 4 firmware15 февр. 2018 г.
- CVE-2020-720969На этой неделе
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
КритическаяCVSS 9,8Готовый эксплойтEPSS 99 %hp · linuxki12 февр. 2020 г.
- CVE-2000-057369На этой неделе
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exec
КритическаяCVSS 10,0Готовый эксплойтEPSS 96 %hp · hp-ux7 июл. 2000 г.
- CVE-2001-079768На этой неделе
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %sgi · irix12 дек. 2001 г.
- CVE-2016-200467На этой неделе
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified ve
КритическаяCVSS 9,8Готовый эксплойтEPSS 94 %hp · data protector21 апр. 2016 г.
- CVE-2014-262367На этой неделе
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
КритическаяCVSS 10,0Готовый эксплойтEPSS 91 %hp · storage data protector17 июл. 2014 г.
- CVE-2013-233367На этой неделе
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unkn
КритическаяCVSS 10,0Готовый эксплойтEPSS 90 %hp · storage data protector6 июн. 2013 г.
- CVE-2011-186567На этой неделе
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to
КритическаяCVSS 10,0Готовый эксплойтEPSS 89 %hp · openview storage data protector1 июл. 2011 г.
- CVE-2003-008566На этой неделе
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al
КритическаяCVSS 10,0Proof of conceptEPSS 86 %samba · samba31 мар. 2003 г.
- CVE-2017-581665На этой неделе
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
КритическаяCVSS 9,8Готовый эксплойтEPSS 86 %hp · intelligent management center15 февр. 2018 г.
- CVE-2003-020165На этой неделе
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
КритическаяCVSS 10,0Готовый эксплойтEPSS 85 %samba · samba5 мая 2003 г.
- CVE-2011-027665На этой неделе
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager
КритическаяCVSS 10,0Готовый эксплойтEPSS 82 %hp · openview performance insight1 февр. 2011 г.
- CVE-2019-573664На этой неделе
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
ВысокаяCVSS 8,6Готовый эксплойтEPSS 98 %docker · docker11 февр. 2019 г.
- CVE-2017-274164На этой неделе
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.
КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %hp · j9v82a firmware23 янв. 2018 г.
- CVE-2017-581764На этой неделе
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
КритическаяCVSS 9,8Готовый эксплойтEPSS 83 %hp · intelligent management center15 февр. 2018 г.
- CVE-2020-720064На этой неделе
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %hp · systems insight manager18 дек. 2020 г.
- CVE-2011-092364На этой неделе
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code
КритическаяCVSS 10,0Готовый эксплойтEPSS 81 %hp · data protector8 февр. 2011 г.
- CVE-2009-384364На этой неделе
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %hp · operations manager23 нояб. 2009 г.
- CVE-2009-418964На этой неделе
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %hp · operations manager3 дек. 2009 г.