Vulnerability index

Browse CVEs

1,743 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Synaptics Touchpad Driver MEDIUM 5.1
CVE-2017-17556

A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by…

Mitigation only
Fix from $1,600 2017-12-15
Content Manager HIGH 7.5
CVE-2017-14360

A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited …

No fix yet
Fix from $1,950 2017-11-08
Performance Center MEDIUM 5.4
CVE-2017-14359

A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to all…

Mitigation only
Fix from $1,600 2017-11-03
Arcsight Enterprise Security Manager CRITICAL 9.8
CVE-2017-14356

An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vul…

Mitigation only
Fix from $2,300 2017-10-31
Arcsight Enterprise Security Manager MEDIUM 6.1
CVE-2017-14357

A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Pa…

Mitigation only
Fix from $1,600 2017-10-31
Arcsight Enterprise Security Manager MEDIUM 6.1
CVE-2017-14358

A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.…

Mitigation only
Fix from $1,600 2017-10-31
Loadrunner CRITICAL 9.8
CVE-2017-5789EPSS 18%

HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified …

Fix: after 12.53
Fix from $2,300 2017-10-11
Intelligent Management Center Plat CRITICAL 9.8
CVE-2017-5791EPSS 69%

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via un…

Mitigation only
Fix from $2,300 2017-10-11
Operations Orchestration CRITICAL 9.8
CVE-2017-8994EPSS 10%

A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.

Fix: after 10.70
Fix from $2,300 2017-10-10
Ucmdb Foundation Software HIGH 8.8
CVE-2017-14353

A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, cou…

No fix yet
Fix from $1,950 2017-10-05
Ucmdb Foundation Software MEDIUM 6.1
CVE-2017-14354

A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.3…

Mitigation only
Fix from $1,600 2017-10-05
Bsm Platform Application Performance Management System Health CRITICAL 9.8
CVE-2017-13983EPSS 6%

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…

Mitigation only
Fix from $2,300 2017-09-30
Sitescope CRITICAL 9.8
CVE-2017-14349

An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon…

Mitigation only
Fix from $2,300 2017-09-30
Application Performance Management CRITICAL 9.8
CVE-2017-14350EPSS 7%

A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulner…

No fix yet
Fix from $2,300 2017-09-30
Ucmdb Configuration Manager CRITICAL 9.8
CVE-2017-14351

A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vul…

No fix yet
Fix from $2,300 2017-09-30
Bsm Platform Application Performance Management System Health HIGH 8.8
CVE-2017-13982

A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows…

Mitigation only
Fix from $1,950 2017-09-30
Arcsight Enterprise Security Manager HIGH 8.1
CVE-2017-13989

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows …

Mitigation only
Fix from $1,950 2017-09-30
Bsm Platform Application Performance Management System Health MEDIUM 6.5
CVE-2017-13984

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…

Mitigation only
Fix from $1,600 2017-09-30
Bsm Platform Application Performance Management System Health MEDIUM 6.5
CVE-2017-13985

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows rem…

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 6.5
CVE-2017-13987

An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, all…

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 6.5
CVE-2017-13988

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows …

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 6.1
CVE-2017-13986

A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch…

Mitigation only
Fix from $1,600 2017-09-30
Ucmdb Configuration Manager MEDIUM 6.1
CVE-2017-14352

A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vul…

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 5.3
CVE-2017-13990

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disc…

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 5.3
CVE-2017-13991

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disc…

Mitigation only
Fix from $1,600 2017-09-30
Linux Imaging And Printing HIGH 8.1
CVE-2015-0839EPSS 6%

The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveragin…

Fix: after 3.17.7
Fix from $1,950 2017-08-02
Helion Openstack Glance HIGH 8.4
CVE-2016-4383

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated user…

Mitigation only
Fix from $1,950 2017-06-27
Integrated Lights Out Firmware HIGH 7.5
CVE-2015-5436

A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and later, but prior to version …

Fix: 2.30+
Fix from $1,950 2017-05-11
Thinpro HIGH 7.8
CVE-2016-2246

HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended…

Patch available
Fix from $1,950 2016-12-29
System Management Homepage HIGH 7.5
CVE-2016-4396

HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" …

Fix: after 7.5.5.0
Fix from $1,950 2016-10-28