VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2018-7071MedAug 6, 2018
    risk 0.28cvss 4.3epss 0.01

    HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.

  • CVE-2024-54009MedDec 19, 2024
    risk 0.26cvss 4.0epss 0.00

    Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

  • CVE-2026-73743LowSep 1, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a…

  • CVE-2024-11856LowDec 2, 2024
    risk 0.24cvss 3.7epss 0.00

    A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.

  • CVE-2016-4379LowSep 8, 2016
    risk 0.24cvss 3.7epss 0.02

    The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay…

  • CVE-2026-73744LowSep 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the…

  • CVE-2025-37109LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

  • CVE-2025-37108LowJul 31, 2025
    risk 0.23cvss 3.5epss 0.00

    Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product

  • CVE-2016-8535LowFeb 15, 2018
    risk 0.23cvss 3.5epss 0.01

    A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2024-54010LowJan 8, 2025
    risk 0.22cvss 3.4epss 0.00

    A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires…

  • CVE-2025-25040LowMar 18, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is…

  • CVE-2010-3282LowJan 9, 2020
    risk 0.21cvss 3.3epss 0.00

    389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local…

  • CVE-2026-73746LowSep 1, 2026
    risk 0.20cvss 3.1epss 0.00

    A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected…

  • CVE-2026-73745LowSep 1, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected system. Successful exploitation could allow an attacker to gain insight into internal services and workflows,…

  • CVE-2026-73747LowSep 1, 2026
    risk 0.16cvss 2.5epss 0.00

    A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected…

  • CVE-2022-37939LowMar 10, 2023
    risk 0.15cvss 2.3epss 0.00

    A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locally exploited to allow disclosure of information. HPE has made the following software to resolve the vulnerability in HPE Superdome Flex…

  • CVE-2026-73748LowSep 1, 2026
    risk 0.14cvss 2.2epss 0.00

    A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially…

  • CVE-2005-3277Oct 21, 2005
    risk 0.05cvss —epss 0.19

    The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different…

  • CVE-2006-5556Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

  • CVE-2006-5557Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to…

  • CVE-2003-1097Dec 31, 2003
    risk 0.03cvss —epss 0.04

    Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

  • CVE-2003-1461Dec 31, 2003
    risk 0.03cvss —epss 0.02

    Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

  • CVE-2003-0840Nov 17, 2003
    risk 0.03cvss —epss 0.01

    Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

  • CVE-2002-1473Apr 22, 2003
    risk 0.03cvss —epss 0.04

    Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

  • CVE-2002-0812Aug 12, 2002
    risk 0.03cvss —epss 0.03

    Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by…

  • CVE-2000-0702Oct 20, 2000
    risk 0.03cvss —epss 0.01

    The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.

  • CVE-2000-0468Jun 2, 2000
    risk 0.03cvss —epss 0.01

    man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.

  • CVE-1999-0050Dec 1, 1996
    risk 0.03cvss —epss 0.01

    Buffer overflow in HP-UX newgrp program.

  • CVE-2004-1332Dec 31, 2004
    risk 0.01cvss —epss 0.10

    Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.

  • CVE-2026-44879HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.02

    A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2026-44878HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper…

  • CVE-2026-44877MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.00

    An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a…

  • CVE-2015-6030Nov 4, 2015
    risk 0.00cvss —epss 0.01

    HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

  • CVE-2015-5444Oct 18, 2015
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-5443Oct 12, 2015
    risk 0.00cvss —epss 0.01

    HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2015-5440Sep 16, 2015
    risk 0.00cvss —epss 0.01

    HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2015-2136Sep 16, 2015
    risk 0.00cvss —epss 0.02

    HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.

  • CVE-2015-5426Sep 16, 2015
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.

  • CVE-2015-5432Aug 27, 2015
    risk 0.00cvss —epss 0.04

    HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2015-5431Aug 27, 2015
    risk 0.00cvss —epss 0.02

    HP Matrix Operating Environment before 7.5.0 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2015-5403Aug 27, 2015
    risk 0.00cvss —epss 0.02

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-2139.

  • CVE-2015-5402Aug 27, 2015
    risk 0.00cvss —epss 0.01

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows local users to gain privileges, and consequently obtain sensitive information, modify data, or cause a denial of service, via unspecified vectors.

  • CVE-2015-2140Aug 27, 2015
    risk 0.00cvss —epss 0.02

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2015-2139Aug 27, 2015
    risk 0.00cvss —epss 0.02

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5403.

  • CVE-2015-5411Aug 26, 2015
    risk 0.00cvss —epss 0.02

    HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2014-2608Dec 10, 2014
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors.

  • CVE-2009-2682Sep 24, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

  • CVE-2007-0396Jan 19, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.

  • CVE-2006-0436Jan 26, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.

  • CVE-2005-3565Nov 16, 2005
    risk 0.00cvss —epss 0.03

    Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.

Page 21 of 22