Vulnerabilities > HP > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-05-30 CVE-2016-1999 Improper Access Control vulnerability in HP Release Control 9.13/9.20/9.21
The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
network
low complexity
hp CWE-284
critical
9.8
2016-05-22 CVE-2016-4543 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
network
low complexity
hp php fedoraproject opensuse CWE-119
critical
9.8
2016-04-21 CVE-2016-2008 Unspecified vulnerability in HP Data Protector
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
hp
critical
9.8
2016-04-21 CVE-2016-2007 Unspecified vulnerability in HP Data Protector
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3354.
network
low complexity
hp
critical
9.8
2016-04-21 CVE-2016-2006 Unspecified vulnerability in HP Data Protector
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3353.
network
low complexity
hp
critical
9.8
2016-04-21 CVE-2016-2005 Unspecified vulnerability in HP Data Protector
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.
network
low complexity
hp
critical
9.8
2016-04-21 CVE-2016-2004 Missing Authentication for Critical Function vulnerability in HP Data Protector
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication.
network
low complexity
hp CWE-306
critical
9.8
2016-04-20 CVE-2016-2003 Unspecified vulnerability in HP products
HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
network
low complexity
hp
critical
9.8
2016-04-20 CVE-2016-2002 Command Injection vulnerability in HP Vertica
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.
network
low complexity
hp CWE-77
critical
9.8
2016-04-05 CVE-2016-2000 Data Processing Errors vulnerability in HP products
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
network
low complexity
hp CWE-19
critical
9.8