VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2022-31645HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31644HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31639HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31638HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31637HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31636HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31635HigJun 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2023-26294HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2022-43778HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-43777HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-27541HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2022-27539HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

  • CVE-2019-16283HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.

  • CVE-2023-28088HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    An HPE OneView appliance dump may expose SAN switch administrative credentials

  • CVE-2022-38396HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This potential vulnerability was remediated starting with Windows…

  • CVE-2022-3990HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for automatic updates should have already received the remediation.

  • CVE-2022-27537HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential…

  • CVE-2022-23455HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

  • CVE-2022-23454HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

  • CVE-2022-23453HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

  • CVE-2021-3809HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.

  • CVE-2021-3808HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.

  • CVE-2021-3439HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.

  • CVE-2022-38395HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.03

    HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance…

  • CVE-2022-1038HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.

  • CVE-2022-23699HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2020-6922HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6921HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6919HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6918HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6917HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2019-18912HigNov 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

  • CVE-2019-18916HigNov 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printers) which may lead to unauthorized elevation of privilege on the client.

  • CVE-2020-6931HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.

  • CVE-2020-28416HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

  • CVE-2021-3440HigNov 1, 2021
    risk 0.51cvss 7.8epss 0.00

    HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevation of privilege.

  • CVE-2021-3438HigMay 20, 2021
    risk 0.51cvss 7.8epss 0.03

    A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

  • CVE-2020-11861HigSep 18, 2020
    risk 0.51cvss 7.8epss 0.00

    Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system.

  • CVE-2019-18619HigJul 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept…

  • CVE-2020-7135HigApr 27, 2020
    risk 0.51cvss 7.8epss 0.01

    A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux. The vulnerable software is included in the HPE Service Pack for ProLiant (SPP) releases 2018.06.0,…

  • CVE-2012-6277HigFeb 21, 2020
    risk 0.51cvss 7.8epss 0.08

    Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before…

  • CVE-2015-0949HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.00

    The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to…

  • CVE-2014-7303HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.

  • CVE-2014-7302HigJan 27, 2020
    risk 0.51cvss 7.8epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.

  • CVE-2019-6329HigJun 25, 2019
    risk 0.51cvss 7.8epss 0.02

    HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.

  • CVE-2019-6328HigJun 25, 2019
    risk 0.51cvss 7.8epss 0.01

    HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.

  • CVE-2018-7118HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.01

    A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software earlier than version 2018.09.0.

  • CVE-2019-3484HigMar 25, 2019
    risk 0.51cvss 7.8epss 0.02

    Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.

  • CVE-2017-8968HigAug 6, 2018
    risk 0.51cvss 7.8epss 0.01

    A remote execution of arbitrary code vulnerability has been identified in HPE RESTful Interface Tool 1.5, 2.0 (hprest-1.5-79.x86_64.rpm, ilorest-2.0-403.x86_64.rpm). The issue is resolved in iLOREST v2.1 or subsequent versions.

  • CVE-2016-4397HigAug 6, 2018
    risk 0.51cvss 7.8epss 0.01

    A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.

Page 15 of 56