Vulnerabilities > Hitachi

DATE CVE VULNERABILITY TITLE RISK
2010-07-02 CVE-2010-2625 Denial-Of-Service vulnerability in Hitachi products
Unspecified vulnerability in the Client Service for DPM in Hitachi ServerConductor / Deployment Manager 01-00, 01-01, and 06-00 through 06-00-/A; ServerConductor / Deployment Manager Standard Edition and Enterprise Edition 07-50 through 07-55, and 07-57 through 07-59; and JP1/ServerConductor/Deployment Manager Standard and Enterprise Edition 07-50 through 07-56-/F, 08-00 through 08-09-/E, 08-50 through 08-80-/A, 08-06 through 08-07, and 08-51 through 08-70; allows attackers to cause a denial of service (shutdown and reboot) via unknown vectors.
network
low complexity
hitachi
7.8
2010-04-21 CVE-2009-4777 Products GIF File Parsing Denial of Service vulnerability in Hitachi
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
4.3
2010-04-21 CVE-2009-4776 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Hitachi products
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.
network
hitachi CWE-119
critical
9.3
2009-09-11 CVE-2009-3172 Unspecified vulnerability in Hitachi products
Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights.
network
low complexity
hitachi
7.5
2009-09-11 CVE-2009-3169 Multiple Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP
Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
hitachi
critical
10.0
2008-12-26 CVE-2008-5719 Cross-Site Scripting vulnerability in Hitachi products
Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi Groupmax Workflow - Development Kit for Active Server Pages before 06-52-/A allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hitachi CWE-79
4.3
2008-12-26 CVE-2008-5717 Cross-Site Scripting vulnerability in Hitachi JP1 Integrated Management Service Support
Cross-site scripting (XSS) vulnerability in Hitachi JP1/Integrated Management - Service Support 08-10 through 08-10-05, 08-11 through 08-11-03, and 08-50 through 08-50-03 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hitachi CWE-79
4.3
2008-05-13 CVE-2008-2172 Improper Input Validation vulnerability in Hitachi Gr2000, Gr3000 and Gr4000
Unspecified vulnerability in Hitachi GR routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
hitachi CWE-20
7.1
2008-05-13 CVE-2008-2169 Improper Input Validation vulnerability in multiple products
Unspecified vulnerability in Avici routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
avici hitachi CWE-20
7.1
2008-02-21 CVE-2008-0876 Improper Input Validation vulnerability in Hitachi Sewb3 Mi-Platform and Sewb3 Platform
Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via "invalid data."
network
hitachi CWE-20
4.3