HP records
2,534 published records for vendor hp.
Researcher profile
- Entered KEV
- 6 · 0.2%
- Weaponized
- 102 · 4%
- Pre-auth RCE
- 539
- With a fix record
- 7%
- Median publish → KEV
- 2799 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')181
- CWE-20 Improper Input Validation160
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer134
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')116
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor106
- CWE-264 Permissions, Privileges, and Access Controls65
The weakness classes this vendor ships most often: where to look.
CWEAll records
2,534 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
93Now | CVE-2013-4810Weaponized | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remhp · application lifecycle management · CWE-94 | Critical9.8 | KEV | 79.5% | Sep 16, 2013 |
91Now | CVE-2005-2773Weaponized | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) hp · openview network node manager · CWE-77 | Critical9.8 | KEV | 74.6% | Sep 2, 2005 |
85Now | CVE-2015-8651Weaponized | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | High8.8 | KEV | 67.7% | Dec 28, 2015 |
70This week | CVE-2017-12542Weaponized | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.hp · integrated lights-out 4 firmware | Critical10.0 | — | 99.3% | Feb 15, 2018 |
69This week | CVE-2020-7209Weaponized | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.hp · linuxki | Critical9.8 | — | 98.8% | Feb 12, 2020 |
69This week | CVE-2000-0573Weaponized | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exechp · hp-ux | Critical10.0 | — | 96.2% | Jul 7, 2000 |
68This week | CVE-2001-0797Weaponized | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Critical10.0 | — | 94.7% | Dec 12, 2001 |
67This week | CVE-2016-2004Weaponized | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vehp · data protector · CWE-306 | Critical9.8 | — | 94.3% | Apr 21, 2016 |
67This week | CVE-2014-2623Weaponized | Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.hp · storage data protector | Critical10.0 | — | 90.7% | Jul 17, 2014 |
67This week | CVE-2013-2333Weaponized | Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknhp · storage data protector | Critical10.0 | — | 89.8% | Jun 6, 2013 |
67This week | CVE-2011-1865Weaponized | Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to hp · openview storage data protector · CWE-119 | Critical10.0 | — | 88.9% | Jul 1, 2011 |
66This week | CVE-2003-0085Proof of concept | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alsamba · samba | Critical10.0 | — | 86.4% | Mar 31, 2003 |
65This week | CVE-2017-5816Weaponized | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Critical9.8 | — | 86.2% | Feb 15, 2018 |
65This week | CVE-2003-0201Weaponized | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Critical10.0 | — | 84.5% | May 5, 2003 |
65This week | CVE-2011-0276Weaponized | HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager hp · openview performance insight | Critical10.0 | — | 82.4% | Feb 1, 2011 |
64This week | CVE-2019-5736Weaponized | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | High8.6 | — | 98.5% | Feb 11, 2019 |
64This week | CVE-2017-2741Weaponized | A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.hp · j9v82a firmware | Critical9.8 | — | 84.6% | Jan 23, 2018 |
64This week | CVE-2017-5817Weaponized | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Critical9.8 | — | 82.6% | Feb 15, 2018 |
64This week | CVE-2020-7200Weaponized | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.hp · systems insight manager | Critical9.8 | — | 81.9% | Dec 18, 2020 |
64This week | CVE-2011-0923Weaponized | The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code hp · data protector · CWE-20 | Critical10.0 | — | 81.1% | Feb 8, 2011 |
64This week | CVE-2009-3843Weaponized | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Critical10.0 | — | 79.0% | Nov 23, 2009 |
64This week | CVE-2009-4189Weaponized | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code hp · operations manager · CWE-255 | Critical10.0 | — | 78.5% | Dec 3, 2009 |
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2013-481093Now
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow rem
CriticalCVSS 9.8KEVWeaponizedEPSS 79%hp · application lifecycle managementSep 16, 2013
- CVE-2005-277391Now
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)
CriticalCVSS 9.8KEVWeaponizedEPSS 75%hp · openview network node managerSep 2, 2005
- CVE-2015-865185Now
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
HighCVSS 8.8KEVWeaponizedEPSS 68%adobe · air sdkDec 28, 2015
- CVE-2017-1254270This week
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
CriticalCVSS 10.0WeaponizedEPSS 99%hp · integrated lights-out 4 firmwareFeb 15, 2018
- CVE-2020-720969This week
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
CriticalCVSS 9.8WeaponizedEPSS 99%hp · linuxkiFeb 12, 2020
- CVE-2000-057369This week
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exec
CriticalCVSS 10.0WeaponizedEPSS 96%hp · hp-uxJul 7, 2000
- CVE-2001-079768This week
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
CriticalCVSS 10.0WeaponizedEPSS 95%sgi · irixDec 12, 2001
- CVE-2016-200467This week
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified ve
CriticalCVSS 9.8WeaponizedEPSS 94%hp · data protectorApr 21, 2016
- CVE-2014-262367This week
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
CriticalCVSS 10.0WeaponizedEPSS 91%hp · storage data protectorJul 17, 2014
- CVE-2013-233367This week
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unkn
CriticalCVSS 10.0WeaponizedEPSS 90%hp · storage data protectorJun 6, 2013
- CVE-2011-186567This week
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to
CriticalCVSS 10.0WeaponizedEPSS 89%hp · openview storage data protectorJul 1, 2011
- CVE-2003-008566This week
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al
CriticalCVSS 10.0Proof of conceptEPSS 86%samba · sambaMar 31, 2003
- CVE-2017-581665This week
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
CriticalCVSS 9.8WeaponizedEPSS 86%hp · intelligent management centerFeb 15, 2018
- CVE-2003-020165This week
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
CriticalCVSS 10.0WeaponizedEPSS 85%samba · sambaMay 5, 2003
- CVE-2011-027665This week
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager
CriticalCVSS 10.0WeaponizedEPSS 82%hp · openview performance insightFeb 1, 2011
- CVE-2019-573664This week
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
HighCVSS 8.6WeaponizedEPSS 98%docker · dockerFeb 11, 2019
- CVE-2017-274164This week
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.
CriticalCVSS 9.8WeaponizedEPSS 85%hp · j9v82a firmwareJan 23, 2018
- CVE-2017-581764This week
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
CriticalCVSS 9.8WeaponizedEPSS 83%hp · intelligent management centerFeb 15, 2018
- CVE-2020-720064This week
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.
CriticalCVSS 9.8WeaponizedEPSS 82%hp · systems insight managerDec 18, 2020
- CVE-2011-092364This week
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code
CriticalCVSS 10.0WeaponizedEPSS 81%hp · data protectorFeb 8, 2011
- CVE-2009-384364This week
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
CriticalCVSS 10.0WeaponizedEPSS 79%hp · operations managerNov 23, 2009
- CVE-2009-418964This week
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code
CriticalCVSS 10.0WeaponizedEPSS 79%hp · operations managerDec 3, 2009