HP kayıtları
hp üreticisine ait 2.534 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 6 · %0,2
- Silahlaştırılmış
- 102 · %4
- Pre-auth RCE
- 539
- Düzeltme kaydı olan
- %7
- Yayından KEV’e ortanca
- 2799 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')181
- CWE-20 Improper Input Validation160
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer134
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')116
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor106
- CWE-264 Permissions, Privileges, and Access Controls65
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
2.534 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2017-5638Silahlaştırılmış | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Kritik9,8 | KEV | %100,0 | 10 Mar 2017 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2015-3113Silahlaştırılmış | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Kritik9,8 | KEV | %99,9 | 23 Haz 2015 |
93Hemen | CVE-2013-4810Silahlaştırılmış | HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remhp · application lifecycle management · CWE-94 | Kritik9,8 | KEV | %79,5 | 16 Eyl 2013 |
91Hemen | CVE-2005-2773Silahlaştırılmış | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) hp · openview network node manager · CWE-77 | Kritik9,8 | KEV | %74,6 | 2 Eyl 2005 |
85Hemen | CVE-2015-8651Silahlaştırılmış | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | Yüksek8,8 | KEV | %67,7 | 28 Ara 2015 |
70Bu hafta | CVE-2017-12542Silahlaştırılmış | A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.hp · integrated lights-out 4 firmware | Kritik10,0 | — | %99,3 | 15 Şub 2018 |
69Bu hafta | CVE-2020-7209Silahlaştırılmış | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.hp · linuxki | Kritik9,8 | — | %98,8 | 12 Şub 2020 |
69Bu hafta | CVE-2000-0573Silahlaştırılmış | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exechp · hp-ux | Kritik10,0 | — | %96,2 | 7 Tem 2000 |
68Bu hafta | CVE-2001-0797Silahlaştırılmış | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Kritik10,0 | — | %94,7 | 12 Ara 2001 |
67Bu hafta | CVE-2016-2004Silahlaştırılmış | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vehp · data protector · CWE-306 | Kritik9,8 | — | %94,3 | 21 Nis 2016 |
67Bu hafta | CVE-2014-2623Silahlaştırılmış | Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.hp · storage data protector | Kritik10,0 | — | %90,7 | 17 Tem 2014 |
67Bu hafta | CVE-2013-2333Silahlaştırılmış | Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknhp · storage data protector | Kritik10,0 | — | %89,8 | 6 Haz 2013 |
67Bu hafta | CVE-2011-1865Silahlaştırılmış | Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to hp · openview storage data protector · CWE-119 | Kritik10,0 | — | %88,9 | 1 Tem 2011 |
66Bu hafta | CVE-2003-0085Kavram kanıtı | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alsamba · samba | Kritik10,0 | — | %86,4 | 31 Mar 2003 |
65Bu hafta | CVE-2017-5816Silahlaştırılmış | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Kritik9,8 | — | %86,2 | 15 Şub 2018 |
65Bu hafta | CVE-2003-0201Silahlaştırılmış | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Kritik10,0 | — | %84,5 | 5 May 2003 |
65Bu hafta | CVE-2011-0276Silahlaştırılmış | HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager hp · openview performance insight | Kritik10,0 | — | %82,4 | 1 Şub 2011 |
64Bu hafta | CVE-2019-5736Silahlaştırılmış | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Yüksek8,6 | — | %98,5 | 11 Şub 2019 |
64Bu hafta | CVE-2017-2741Silahlaştırılmış | A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.hp · j9v82a firmware | Kritik9,8 | — | %84,6 | 23 Oca 2018 |
64Bu hafta | CVE-2017-5817Silahlaştırılmış | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.hp · intelligent management center · CWE-20 | Kritik9,8 | — | %82,6 | 15 Şub 2018 |
64Bu hafta | CVE-2020-7200Silahlaştırılmış | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.hp · systems insight manager | Kritik9,8 | — | %81,9 | 18 Ara 2020 |
64Bu hafta | CVE-2011-0923Silahlaştırılmış | The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code hp · data protector · CWE-20 | Kritik10,0 | — | %81,1 | 8 Şub 2011 |
64Bu hafta | CVE-2009-3843Silahlaştırılmış | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Kritik10,0 | — | %79,0 | 23 Kas 2009 |
64Bu hafta | CVE-2009-4189Silahlaştırılmış | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code hp · operations manager · CWE-255 | Kritik10,0 | — | %78,5 | 3 Ara 2009 |
- CVE-2017-563899Hemen
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · struts10 Mar 2017
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2015-311399Hemen
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player23 Haz 2015
- CVE-2013-481093Hemen
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow rem
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %79hp · application lifecycle management16 Eyl 2013
- CVE-2005-277391Hemen
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %75hp · openview network node manager2 Eyl 2005
- CVE-2015-865185Hemen
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %68adobe · air sdk28 Ara 2015
- CVE-2017-1254270Bu hafta
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
KritikCVSS 10,0SilahlaştırılmışEPSS %99hp · integrated lights-out 4 firmware15 Şub 2018
- CVE-2020-720969Bu hafta
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
KritikCVSS 9,8SilahlaştırılmışEPSS %99hp · linuxki12 Şub 2020
- CVE-2000-057369Bu hafta
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to exec
KritikCVSS 10,0SilahlaştırılmışEPSS %96hp · hp-ux7 Tem 2000
- CVE-2001-079768Bu hafta
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
KritikCVSS 10,0SilahlaştırılmışEPSS %95sgi · irix12 Ara 2001
- CVE-2016-200467Bu hafta
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified ve
KritikCVSS 9,8SilahlaştırılmışEPSS %94hp · data protector21 Nis 2016
- CVE-2014-262367Bu hafta
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
KritikCVSS 10,0SilahlaştırılmışEPSS %91hp · storage data protector17 Tem 2014
- CVE-2013-233367Bu hafta
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unkn
KritikCVSS 10,0SilahlaştırılmışEPSS %90hp · storage data protector6 Haz 2013
- CVE-2011-186567Bu hafta
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to
KritikCVSS 10,0SilahlaştırılmışEPSS %89hp · openview storage data protector1 Tem 2011
- CVE-2003-008566Bu hafta
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al
KritikCVSS 10,0Kavram kanıtıEPSS %86samba · samba31 Mar 2003
- CVE-2017-581665Bu hafta
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
KritikCVSS 9,8SilahlaştırılmışEPSS %86hp · intelligent management center15 Şub 2018
- CVE-2003-020165Bu hafta
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
KritikCVSS 10,0SilahlaştırılmışEPSS %85samba · samba5 May 2003
- CVE-2011-027665Bu hafta
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager
KritikCVSS 10,0SilahlaştırılmışEPSS %82hp · openview performance insight1 Şub 2011
- CVE-2019-573664Bu hafta
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
YüksekCVSS 8,6SilahlaştırılmışEPSS %98docker · docker11 Şub 2019
- CVE-2017-274164Bu hafta
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.
KritikCVSS 9,8SilahlaştırılmışEPSS %85hp · j9v82a firmware23 Oca 2018
- CVE-2017-581764Bu hafta
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
KritikCVSS 9,8SilahlaştırılmışEPSS %83hp · intelligent management center15 Şub 2018
- CVE-2020-720064Bu hafta
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6.
KritikCVSS 9,8SilahlaştırılmışEPSS %82hp · systems insight manager18 Ara 2020
- CVE-2011-092364Bu hafta
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code
KritikCVSS 10,0SilahlaştırılmışEPSS %81hp · data protector8 Şub 2011
- CVE-2009-384364Bu hafta
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
KritikCVSS 10,0SilahlaştırılmışEPSS %79hp · operations manager23 Kas 2009
- CVE-2009-418964Bu hafta
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code
KritikCVSS 10,0SilahlaştırılmışEPSS %79hp · operations manager3 Ara 2009