Vulnerability index

Browse CVEs

245 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connected Backup HIGH 7.8
CVE-2017-14355

A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally t…

No fix yet
Fix from $1,950 2017-12-05
Bi Directional Driver HIGH 7.5
CVE-2017-9272

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

Fix: after 4.0.2.0
Fix from $1,950 2017-10-06
Bi Directional Driver MEDIUM 5.3
CVE-2017-9273

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.

Fix: after 4.0.2.0
Fix from $1,600 2017-10-06
Visibroker CRITICAL 9.8
CVE-2017-9282

An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker …

No fix yet
Fix from $2,300 2017-09-21
Visibroker CRITICAL 9.8
CVE-2017-9283

An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further atta…

No fix yet
Fix from $2,300 2017-09-21
Visibroker HIGH 7.5
CVE-2017-9281

An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of…

Mitigation only
Fix from $1,950 2017-09-21
Enterprise Developer CRITICAL 9.8
CVE-2017-7420

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterpr…

Fix: after 2.3
Fix from $2,300 2017-08-21
Directory Server HIGH 8.8
CVE-2017-5187

A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Deve…

Fix: after 2.3
Fix from $1,950 2017-08-21
Enterprise Developer HIGH 8.8
CVE-2017-7423

A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 befor…

Mitigation only
Fix from $1,950 2017-08-21
Enterprise Developer MEDIUM 6.5
CVE-2017-7424

A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, a…

Mitigation only
Fix from $1,600 2017-08-21
Directory Server MEDIUM 6.1
CVE-2017-7421

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (…

Fix: after 2.3
Fix from $1,600 2017-08-21
Enterprise Developer MEDIUM 5.4
CVE-2017-7422

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3,…

Mitigation only
Fix from $1,600 2017-08-21
Sentinel HIGH 7.5
CVE-2017-5185

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

Fix: 8.0.1+
Fix from $1,950 2017-03-30
Sentinel MEDIUM 5.3
CVE-2017-5184

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

Fix: 8.0.1+
Fix from $1,600 2017-03-30
Host Access Management And Security Server MEDIUM 6.5
CVE-2016-5765

Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gatew…

Mitigation only
Fix from $1,600 2016-11-29
Rumba CRITICAL 9.8
CVE-2016-9176

Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers a…

Fix: after 9.4.0
Fix from $2,300 2016-11-04
Rumba Ftp HIGH 8.8
CVE-2016-5764EPSS 8%

Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (…

No fix yet
Fix from $1,950 2016-10-27
Rumba CRITICAL 9.8
CVE-2016-5228EPSS 15%

Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9…

No fix yet
Fix from $2,300 2016-07-03
Rumba CRITICAL 9.8
CVE-2016-1606EPSS 46%

Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2016-07-03
Self Service Password Reset MEDIUM 6.1
CVE-2016-1599

Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject a…

Mitigation only
Fix from $1,600 2016-03-24
Arcsight Enterprise Security Manager HIGH 8.0
CVE-2016-1991

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authent…

Fix: after 5.6
Fix from $1,950 2016-03-16
Arcsight Enterprise Security Manager HIGH 7.8
CVE-2016-1990

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to…

Fix: after 5.6
Fix from $1,950 2016-03-16
Accurev HIGH 9.3
CVE-2015-6946EPSS 21%

Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via …

No fix yet
Fix from $1,950 2015-09-15
Security Solutions For Iseries MEDIUM 6.8
CVE-2015-0795

Multiple stack-based buffer overflows in the SafeShellExecute method in the NetIQExecObject.NetIQExec.1 ActiveX control in NetIQExec.dll in NetIQ Sec…

Mitigation only
Fix from $1,600 2015-07-18
Arcsight Enterprise Security Manager HIGH 10.0
CVE-2014-7885

Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.

Fix: after 6.5c
Fix from $1,950 2015-03-14
Access Manager MEDIUM 6.8
CVE-2014-5217

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4…

No fix yet
Fix from $1,600 2014-12-23
Security Manager HIGH 7.5
CVE-2014-0602

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote a…

Fix: after 6.5.4
Fix from $1,950 2014-07-07
Sentinel MEDIUM 6.8
CVE-2014-3460

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attack…

Mitigation only
Fix from $1,600 2014-05-20
Edirectory HIGH 10.0
CVE-2012-0432EPSS 59%

Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecifie…

Mitigation only
Fix from $1,950 2012-12-25
Edirectory MEDIUM 6.4
CVE-2012-0430

Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an admin…

Mitigation only
Fix from $1,600 2012-12-25