Vendor CVEs
Microfocus
All CVEs
2,790 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-3480 | Med | 0.40 | 6.1 | 0.02 | Mar 25, 2019 | Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7. | ||
| CVE-2018-17952 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2018 | Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 | ||
| CVE-2018-17949 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2018 | Cross site scripting vulnerability in iManager prior to 3.1 SP2. | ||
| CVE-2018-17948 | Med | 0.40 | 6.1 | 0.01 | Nov 20, 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. | ||
| CVE-2018-12480 | Med | 0.40 | 6.1 | 0.01 | Nov 15, 2018 | Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3. | ||
| CVE-2018-7692 | Med | 0.40 | 6.1 | 0.01 | Aug 9, 2018 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. | ||
| CVE-2018-7091 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr. | ||
| CVE-2018-7090 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr. | ||
| CVE-2018-7075 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version. | ||
| CVE-2018-7068 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version. | ||
| CVE-2017-9002 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session… | ||
| CVE-2016-4406 | Med | 0.40 | 6.1 | 0.03 | Aug 6, 2018 | A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44. | ||
| CVE-2018-7680 | Med | 0.40 | 6.1 | 0.01 | Jun 21, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values. | ||
| CVE-2018-9027 | Med | 0.40 | 6.1 | 0.01 | Jun 18, 2018 | A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link. | ||
| CVE-2017-8945 | Med | 0.40 | 6.1 | 0.02 | Feb 15, 2018 | A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found. | ||
| CVE-2016-8517 | Med | 0.40 | 6.1 | 0.02 | Feb 15, 2018 | A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found. | ||
| CVE-2017-2746 | Med | 0.40 | 6.1 | 0.01 | Jan 23, 2018 | Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to create a denial of service. | ||
| CVE-2017-2745 | Med | 0.40 | 6.1 | 0.01 | Jan 23, 2018 | Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to execute scripts in a user's browser. | ||
| CVE-2017-2743 | Med | 0.40 | 6.1 | 0.02 | Jan 23, 2018 | HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be… | ||
| CVE-2018-2641 | Med | 0.40 | 6.1 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2017-14358 | Med | 0.40 | 6.1 | 0.02 | Oct 31, 2017 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | ||
| CVE-2017-14357 | Med | 0.40 | 6.1 | 0.02 | Oct 31, 2017 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) | ||
| CVE-2017-14354 | Med | 0.40 | 6.1 | 0.02 | Oct 5, 2017 | A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting. | ||
| CVE-2017-14352 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2017 | A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow cross-site scripting. | ||
| CVE-2017-13986 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2017 | A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system. | ||
| CVE-2017-7421 | Med | 0.40 | 6.1 | 0.02 | Aug 21, 2017 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1… | ||
| CVE-2017-7430 | Med | 0.40 | 6.1 | 0.01 | May 3, 2017 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework. | ||
| CVE-2017-5191 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2017 | An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header. | ||
| CVE-2017-5183 | Med | 0.40 | 6.1 | 0.01 | Apr 20, 2017 | NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document. | ||
| CVE-2016-5761 | Med | 0.40 | 6.1 | 0.02 | Apr 20, 2017 | Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email. | ||
| CVE-2016-5760 | Med | 0.40 | 6.1 | 0.02 | Apr 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2)… | ||
| CVE-2016-5756 | Med | 0.40 | 6.1 | 0.01 | Mar 23, 2017 | Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl,… | ||
| CVE-2016-5751 | Med | 0.40 | 6.1 | 0.01 | Mar 23, 2017 | An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials. | ||
| CVE-2016-1592 | Med | 0.40 | 6.1 | 0.01 | Oct 27, 2016 | XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. | ||
| CVE-2015-0787 | Med | 0.40 | 6.1 | 0.01 | Oct 27, 2016 | XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI. | ||
| CVE-2016-4363 | Med | 0.40 | 6.1 | 0.03 | Jun 8, 2016 | HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors. | ||
| CVE-2016-1599 | Med | 0.40 | 6.1 | 0.02 | Mar 24, 2016 | Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | ||
| CVE-2024-2207 | Med | 0.39 | 6.0 | 0.00 | Nov 12, 2024 | Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities. | ||
| CVE-2021-22527 | Med | 0.39 | 6.0 | 0.01 | Sep 13, 2021 | Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | ||
| CVE-2019-18618 | Med | 0.39 | 6.0 | 0.01 | Jul 22, 2020 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an… | ||
| CVE-2018-2973 | Med | 0.39 | 5.9 | 0.05 | Jul 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2018-6490 | Med | 0.39 | 5.9 | 0.03 | Mar 2, 2018 | Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service. | ||
| CVE-2018-2618 | Med | 0.39 | 5.9 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows… | ||
| CVE-2017-14360 | Med | 0.39 | 5.9 | 0.02 | Nov 8, 2017 | A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS). | ||
| CVE-2016-8106 | Med | 0.39 | 5.9 | 0.04 | Jan 9, 2017 | A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions. | ||
| CVE-2016-2244 | Med | 0.39 | 5.9 | 0.03 | Mar 4, 2016 | HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors. | ||
| CVE-2000-0972 | Med | 0.39 | 5.5 | 0.01 | Dec 19, 2000 | HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates. | ||
| CVE-2026-42626 | Med | 0.38 | 5.9 | 0.00 | May 22, 2026 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets,… | ||
| CVE-2025-0858 | Med | 0.38 | — | 0.00 | Feb 5, 2025 | A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure. | ||
| CVE-2023-7240 | Med | 0.38 | 5.8 | 0.00 | May 7, 2024 | An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to… |
- risk 0.40cvss 6.1epss 0.02
Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
- risk 0.40cvss 6.1epss 0.01
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
- risk 0.40cvss 6.1epss 0.01
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
- risk 0.40cvss 6.1epss 0.01
Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.
- risk 0.40cvss 6.1epss 0.01
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
- risk 0.40cvss 6.1epss 0.01
HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.
- risk 0.40cvss 6.1epss 0.01
HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.
- risk 0.40cvss 6.1epss 0.01
A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version.
- risk 0.40cvss 6.1epss 0.01
HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.
- risk 0.40cvss 6.1epss 0.01
All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session…
- risk 0.40cvss 6.1epss 0.03
A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.
- risk 0.40cvss 6.1epss 0.01
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.
- risk 0.40cvss 6.1epss 0.02
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
- risk 0.40cvss 6.1epss 0.02
A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.
- risk 0.40cvss 6.1epss 0.01
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to create a denial of service.
- risk 0.40cvss 6.1epss 0.01
Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to execute scripts in a user's browser.
- risk 0.40cvss 6.1epss 0.02
HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be…
- risk 0.40cvss 6.1epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.40cvss 6.1epss 0.02
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
- risk 0.40cvss 6.1epss 0.02
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)
- risk 0.40cvss 6.1epss 0.02
A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting.
- risk 0.40cvss 6.1epss 0.01
A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow cross-site scripting.
- risk 0.40cvss 6.1epss 0.01
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.
- risk 0.40cvss 6.1epss 0.02
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1…
- risk 0.40cvss 6.1epss 0.01
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
- risk 0.40cvss 6.1epss 0.01
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
- risk 0.40cvss 6.1epss 0.01
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2)…
- risk 0.40cvss 6.1epss 0.01
Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl,…
- risk 0.40cvss 6.1epss 0.01
An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.
- risk 0.40cvss 6.1epss 0.01
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
- risk 0.40cvss 6.1epss 0.01
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
- risk 0.40cvss 6.1epss 0.03
HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
- risk 0.39cvss 6.0epss 0.00
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.
- risk 0.39cvss 6.0epss 0.01
Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
- risk 0.39cvss 6.0epss 0.01
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an…
- risk 0.39cvss 5.9epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.39cvss 5.9epss 0.03
Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.
- risk 0.39cvss 5.9epss 0.05
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…
- risk 0.39cvss 5.9epss 0.02
A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).
- risk 0.39cvss 5.9epss 0.04
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.
- risk 0.39cvss 5.9epss 0.03
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
- risk 0.39cvss 5.5epss 0.01
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
- risk 0.38cvss 5.9epss 0.00
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets,…
- risk 0.38cvss —epss 0.00
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
- risk 0.38cvss 5.8epss 0.00
An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to…
Page 23 of 56