VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2017-3210HigJul 24, 2018
    risk 0.51cvss 7.8epss 0.01

    Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These…

  • CVE-2018-7687HigMay 21, 2018
    risk 0.51cvss 7.8epss 0.00

    The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.

  • CVE-2017-8951HigFeb 15, 2018
    risk 0.51cvss 7.8epss 0.01

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

  • CVE-2017-5829HigFeb 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An access restriction bypass vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

  • CVE-2017-17482HigFeb 7, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line.…

  • CVE-2017-2747HigJan 23, 2018
    risk 0.51cvss 7.8epss 0.02

    HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310,…

  • CVE-2017-2740HigJan 23, 2018
    risk 0.51cvss 7.8epss 0.01

    A potential security vulnerability has been identified with the command line shell of the HP ThinPro operating system 6.1, 5.2.1, 5.2, 5.1, 5.0, and 4.4. The vulnerability could result in a local unauthorized elevation of privilege on an HP thin client device.

  • CVE-2016-2246HigDec 29, 2016
    risk 0.51cvss 7.8epss 0.01

    HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended access restrictions and gain privileges via unspecified vectors.

  • CVE-2016-4386HigSep 29, 2016
    risk 0.51cvss 7.8epss 0.00

    HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.

  • CVE-2016-1990HigMar 16, 2016
    risk 0.51cvss 7.8epss 0.00

    HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

  • CVE-2016-2243HigMar 4, 2016
    risk 0.51cvss 7.9epss 0.00

    Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.

  • CVE-2015-6859HigJan 5, 2016
    risk 0.51cvss 7.8epss 0.01

    HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860.

  • CVE-2002-1796HigDec 31, 2002
    risk 0.51cvss 7.8epss 0.00

    ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.

  • CVE-1999-0022HigJul 3, 1996
    risk 0.51cvss 7.8epss 0.00

    Local user gains root privileges via buffer overflow in rdist, via expstr() function.

  • CVE-2026-12556HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2026-12555HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2024-4555HigAug 28, 2024
    risk 0.50cvss 7.7epss 0.00

    Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1

  • CVE-2024-28893HigMay 1, 2024
    risk 0.50cvss 7.7epss 0.00

    Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs).

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2019-3683HigJan 17, 2020
    risk 0.50cvss 8.8epss 0.01

    The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify,…

  • CVE-2018-7116HigDec 3, 2018
    risk 0.50cvss 7.5epss 0.06

    HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via dbman Opcode 10003 'Filename'. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

  • CVE-2018-2794HigApr 19, 2018
    risk 0.50cvss 7.7epss 0.01

    Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the…

  • CVE-2017-8955HigFeb 15, 2018
    risk 0.50cvss 7.5epss 0.08

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

  • CVE-2017-5822HigFeb 15, 2018
    risk 0.50cvss 7.5epss 0.07

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

  • CVE-2017-5818HigFeb 15, 2018
    risk 0.50cvss 7.5epss 0.08

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

  • CVE-2017-5811HigFeb 15, 2018
    risk 0.50cvss 7.5epss 0.09

    A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

  • CVE-2017-5808HigFeb 15, 2018
    risk 0.50cvss 7.5epss 0.10

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

  • CVE-2016-8529HigFeb 15, 2018
    risk 0.50cvss 7.6epss 0.02

    A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.

  • CVE-2017-3733HigMay 4, 2017
    risk 0.50cvss 7.5epss 0.07

    During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

  • CVE-2016-4374HigAug 8, 2016
    risk 0.50cvss 7.7epss 0.02

    HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors.

  • CVE-2016-4447HigJun 9, 2016
    risk 0.50cvss 7.5epss 0.11

    The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

  • CVE-2016-1996HigMar 18, 2016
    risk 0.50cvss 7.7epss 0.01

    HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2015-3200HigJun 9, 2015
    risk 0.50cvss 7.5epss 0.07

    mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

  • CVE-2004-0079HigNov 23, 2004
    risk 0.50cvss 7.5epss 0.10

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

  • CVE-2026-13753HigJul 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.

  • CVE-2026-11877HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

  • CVE-2025-12785HigNov 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

  • CVE-2025-43024HigOct 28, 2025
    risk 0.49cvss 7.5epss 0.00

    A GUI dialog of an application allows to view what files are in the file system without proper authorization.

  • CVE-2025-43025HigJul 2, 2025
    risk 0.49cvss 7.5epss 0.00

    HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 or older (e.g., v7.3.x, v7.2.x, v7.1.x, etc.).

  • CVE-2025-2268HigMar 14, 2025
    risk 0.49cvss 7.5epss 0.00

    The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).

  • CVE-2023-24466HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

  • CVE-2022-26324HigNov 22, 2024
    risk 0.49cvss 7.6epss 0.00

    Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2020-11859HigNov 6, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

  • CVE-2024-9579HigNov 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.

  • CVE-2024-5749HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

  • CVE-2021-22532HigSep 12, 2024
    risk 0.49cvss 7.6epss 0.00

    Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

  • CVE-2024-2301HigMay 23, 2024
    risk 0.49cvss 7.6epss 0.00

    Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device.

  • CVE-2024-3967HigMay 15, 2024
    risk 0.49cvss 7.6epss 0.01

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

  • CVE-2024-1869HigMar 1, 2024
    risk 0.49cvss 7.5epss 0.02

    Certain HP DesignJet print products are potentially vulnerable to information disclosure related to accessing memory out-of-bounds when using the general-purpose gateway (GGW) over port 9220.

  • CVE-2023-50275HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

Page 16 of 56