Skip to content
Noroxi

HP records

2,534 published records for vendor hp.

All records

2,534 records
  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · strutsMar 10, 2017

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerJun 23, 2015

  • HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow rem

    CriticalCVSS 9.8KEVWeaponizedEPSS 79%

    hp · application lifecycle managementSep 16, 2013

  • HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)

    CriticalCVSS 9.8KEVWeaponizedEPSS 75%

    hp · openview network node managerSep 2, 2005

  • Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on

    HighCVSS 8.8KEVWeaponizedEPSS 68%

    adobe · air sdkDec 28, 2015

  • CVE-2017-12542
    70This week

    A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

    CriticalCVSS 10.0WeaponizedEPSS 99%

    hp · integrated lights-out 4 firmwareFeb 15, 2018

  • CVE-2020-7209
    69This week

    LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

    CriticalCVSS 9.8WeaponizedEPSS 99%

    hp · linuxkiFeb 12, 2020

  • CVE-2000-0573
    69This week

    The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exec

    CriticalCVSS 10.0WeaponizedEPSS 96%

    hp · hp-uxJul 7, 2000

  • CVE-2001-0797
    68This week

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe

    CriticalCVSS 10.0WeaponizedEPSS 95%

    sgi · irixDec 12, 2001

  • CVE-2016-2004
    67This week

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified ve

    CriticalCVSS 9.8WeaponizedEPSS 94%

    hp · data protectorApr 21, 2016

  • CVE-2014-2623
    67This week

    Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

    CriticalCVSS 10.0WeaponizedEPSS 91%

    hp · storage data protectorJul 17, 2014

  • CVE-2013-2333
    67This week

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unkn

    CriticalCVSS 10.0WeaponizedEPSS 90%

    hp · storage data protectorJun 6, 2013

  • CVE-2011-1865
    67This week

    Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to

    CriticalCVSS 10.0WeaponizedEPSS 89%

    hp · openview storage data protectorJul 1, 2011

  • CVE-2003-0085
    66This week

    Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al

    CriticalCVSS 10.0Proof of conceptEPSS 86%

    samba · sambaMar 31, 2003

  • CVE-2017-5816
    65This week

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    CriticalCVSS 9.8WeaponizedEPSS 86%

    hp · intelligent management centerFeb 15, 2018

  • CVE-2003-0201
    65This week

    Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG

    CriticalCVSS 10.0WeaponizedEPSS 85%

    samba · sambaMay 5, 2003

  • CVE-2011-0276
    65This week

    HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager

    CriticalCVSS 10.0WeaponizedEPSS 82%

    hp · openview performance insightFeb 1, 2011

  • CVE-2019-5736
    64This week

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen

    HighCVSS 8.6WeaponizedEPSS 98%

    docker · dockerFeb 11, 2019

  • CVE-2017-2741
    64This week

    A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.

    CriticalCVSS 9.8WeaponizedEPSS 85%

    hp · j9v82a firmwareJan 23, 2018

  • CVE-2017-5817
    64This week

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    CriticalCVSS 9.8WeaponizedEPSS 83%

    hp · intelligent management centerFeb 15, 2018

  • CVE-2020-7200
    64This week

    A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.

    CriticalCVSS 9.8WeaponizedEPSS 82%

    hp · systems insight managerDec 18, 2020

  • CVE-2011-0923
    64This week

    The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code

    CriticalCVSS 10.0WeaponizedEPSS 81%

    hp · data protectorFeb 8, 2011

  • CVE-2009-3843
    64This week

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers

    CriticalCVSS 10.0WeaponizedEPSS 79%

    hp · operations managerNov 23, 2009

  • CVE-2009-4189
    64This week

    HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code

    CriticalCVSS 10.0WeaponizedEPSS 79%

    hp · operations managerDec 3, 2009