← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Cisco
DigiHp+1 more
6Nx Os
SarosTcp/ip+3 more
Nov 3, 2025
Jun 2, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack...Show more
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.Show less
1Hp
1Service Pack For Proliant
Nov 21, 2024
Apr 27, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux. The vulnerable software is included in the...Show more
A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux. The vulnerable software is included in the HPE Service Pack for ProLiant (SPP) releases 2018.06.0, 2018.09.0, and 2018.11.0. The vulnerable software is the Supplemental Update / Online ROM Flash Component for Linux (x64) software. The installer in this software component could be locally exploited to execute arbitrary code. Drive Models can be found in the Vulnerability Resolution field of the security bulletin. The 2019_03 SPP and Supplemental update / Online ROM Flash Component for Linux (x64) after 2019.03.0 has fixed this issue.Show less
1Hp
1Hpe Iot + Gcp
Nov 21, 2024
Apr 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.
1Hp
1Hpe Iot + Gcp
Nov 21, 2024
Apr 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.
1Hp
3Blade Maintenance Entity
Integrated Maintenance EntityMaintenance Entity
Nov 21, 2024
Apr 24, 2020
N/A· v4
9.0 CRITICAL· v3
9.0 HIGH· v2
This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintenance Entity products. All J/H-series NonStop systems have a security vulnerability associated with an...Show more
This document describes a security vulnerability in Blade Maintenance Entity, Integrated Maintenance Entity and Maintenance Entity products. All J/H-series NonStop systems have a security vulnerability associated with an open UDP port 17185 on the Maintenance LAN which could result in information disclosure, denial-of-service attacks or local memory corruption against the affected system and a complete control of the system may also be possible. This vulnerability exists only if one gains access to the Maintenance LAN to which Blade Maintenance Entity, Integrated Maintenance Entity or Maintenance Entity product is connected. **Workaround:** Block the UDP port 17185(In the Maintenance LAN Network Switch/Firewall). Fix: Install following SPRs, which are already available: * T1805A01^AAI (Integrated Maintenance Entity) * T4805A01^AAZ (Blade Maintenance Entity). These SPRs are also usable with the following RVUs: * J06.19.00 ? J06.23.01. No fix planned for the following RVUs: J06.04.00 ? J06.18.01. No fix planned for H-Series NonStop systems. No fix planned for the product T2805 (Maintenance Entity).Show less
1Hp
1Onboard Administrator
Nov 21, 2024
Apr 23, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and...Show more
A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE Onboard Administrator. * OA 4.95 (Linux and Windows).Show less
1Hp
8Deskjet Ink Advantage 5000 M2u86a Firmware
Deskjet Ink Advantage 5000 M2u89b FirmwareEnvy 5000 M2u85a Firmware+5 more
Nov 21, 2024
Mar 16, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
1Hp
1Storage Essentials
Nov 21, 2024
Mar 10, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
1Hp
1Oneview Global Dashboard
Nov 21, 2024
Mar 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is res...Show more
HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.Show less
3Hp
IbmSymantec
7Autonomy Keyview Idol
Data Loss Prevention EndpointData Loss Prevention Enforce/detection Servers+4 more
Nov 21, 2024
Feb 21, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gatewa...Show more
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."Show less
1Hp
1Linuxki
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
1Hp
1Linuxki
Nov 21, 2024
Feb 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
1Hp
1System Event Utility
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Ev...Show more
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.Show less
1Hp
1Systems Insight Manager
Nov 21, 2024
Feb 10, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
1Hp
3Asset Manager
Asset Manager Cloudsystem ChargebackSitescope
Nov 21, 2024
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, whic...Show more
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.Show less
1Hp
1Bromium
Nov 21, 2024
Feb 3, 2020
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.
1Hp
33Elite Dragonfly Firmware
Elite X2 G4 FirmwareElitebook 830 G6 Firmware+30 more
Nov 21, 2024
Jan 31, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized ha...Show more
A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs that support Microsoft Windows 10 Kernel DMA protection. Affected versions depend on platform (prior to 01.04.02; or prior to 02.04.01; or prior to 02.04.02).Show less
2Dell
Hp
2Elitebook 850 G1 Firmware
Latitude E6430 Firmware
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls oper...Show more
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to bypass the Secure Boot protection mechanism and gain privileges by leveraging write access to physical memory.Show less
1Hp
3Web Viewpoint T0320
Web Viewpoint T0952Web Viewpoint T0986
Nov 21, 2024
Jan 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file cont...Show more
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.Show less
1Hp
1Sgi Tempo
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.