VYPR

Vendor CVEs

Microfocus

All CVEs

2,781 total · sorted by risk
  • CVE-2024-42394CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-42393CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2024-4143CriJul 15, 2024
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware updates to mitigate this vulnerability.

  • CVE-2024-31473CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31472CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31471CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31470CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port…

  • CVE-2024-31469CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31468CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful…

  • CVE-2024-31467CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-31466CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-1148CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

  • CVE-2024-0794CriFeb 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.

  • CVE-2023-45616CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful…

  • CVE-2023-45615CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-45614CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-5365CriOct 9, 2023
    risk 0.64cvss 9.8epss 0.01

    HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2023-4501CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0…

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2023-35982CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35981CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35980CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-26301CriJul 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.

  • CVE-2023-35175CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

  • CVE-2023-1329CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.

  • CVE-2023-32674CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.

  • CVE-2023-32673CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.

  • CVE-2023-26295CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-22786CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22785CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22784CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22783CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22782CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22781CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22780CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-22779CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-27973CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

  • CVE-2023-27972CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

  • CVE-2023-27971CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

  • CVE-2023-24468CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2

  • CVE-2022-44750CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2021-3942CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.

  • CVE-2021-3919CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability.

  • CVE-2021-3821CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.

  • CVE-2022-28722CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain HP Print Products are potentially vulnerable to Buffer Overflow.

  • CVE-2022-28721CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Certain HP Print Products are potentially vulnerable to Remote Code Execution.

  • CVE-2022-28616CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-28617CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

Page 3 of 56