← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Service Manager
May 6, 2026
Mar 22, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
1Hp
2Operations Orchestration
Operations Orchestration Content
May 6, 2026
Mar 22, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Co...Show more
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.Show less
1Hp
1Support Assistant
May 6, 2026
Mar 19, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.
1Hp
1System Management Homepage
May 6, 2026
Mar 18, 2016
N/A· v4
7.7 HIGH· v3
3.6 LOW· v2
HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.
1Hp
1System Management Homepage
May 6, 2026
Mar 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.
1Hp
1System Management Homepage
May 6, 2026
Mar 18, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Hp
1System Management Homepage
May 6, 2026
Mar 18, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
1Hp
2Enterprise Security Manager
Enterprise Security Manager Express
May 6, 2026
Mar 17, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Hp
1Network Automation
May 6, 2026
Mar 15, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988...Show more
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988.Show less
1Hp
1Network Automation
May 6, 2026
Mar 15, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989...Show more
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.Show less
1Hp
1Futuresmart Firmware
May 6, 2026
Mar 4, 2016
N/A· v4
5.9 MEDIUM· v3
5.0 MEDIUM· v2
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
1Hp
71000 Series Firmware
700 Series Firmware800 Series Firmware+4 more
May 6, 2026
Mar 4, 2016
N/A· v4
7.9 HIGH· v3
5.4 MEDIUM· v2
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
1Hp
1Hp Ux Ipfilter
May 6, 2026
Feb 18, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
10Canonical
DebianF5+7 more
30Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+27 more
May 6, 2026
Feb 18, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash...Show more
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.Show less
1Hp
1Continuous Delivery Automation
May 6, 2026
Feb 12, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
5Canonical
DebianGoogle+2 more
5Android
Debian LinuxLinux Kernel+2 more
May 6, 2026
Feb 8, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of se...Show more
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.Show less
1Hp
1Operations Manager
May 6, 2026
Jan 30, 2016
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
1Hp
1Arcsight Logger
May 6, 2026
Jan 16, 2016
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
1Hp
1Arcsight Logger
May 6, 2026
Jan 16, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
5Apple
HpOpenbsd+2 more
6Linux
Mac Os XOpenssh+3 more
May 29, 2026
Jan 14, 2016
N/A· v4
8.1 HIGH· v3
4.6 MEDIUM· v2
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection fi...Show more
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.Show less