Vulnerabilities > HP > High

DATE CVE VULNERABILITY TITLE RISK
2019-06-25 CVE-2019-6328 Unspecified vulnerability in HP Support Assistant 8.1.40.3/8.7.50
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files.
local
low complexity
hp
7.8
2019-06-17 CVE-2019-6326 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP products
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v.
network
low complexity
hp CWE-119
7.2
2019-06-17 CVE-2019-6325 Cross-Site Request Forgery (CSRF) vulnerability in HP products
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v.
network
low complexity
hp CWE-352
8.8
2019-06-05 CVE-2019-11983 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP products
A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
network
high complexity
hp CWE-119
7.0
2019-06-05 CVE-2019-11982 Cross-site Scripting vulnerability in HP products
A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
network
high complexity
hp CWE-79
8.3
2019-06-05 CVE-2019-11986 Expression Language Injection vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-917
8.8
2019-06-05 CVE-2019-11985 Expression Language Injection vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-917
8.8
2019-06-05 CVE-2019-11984 SQL Injection vulnerability in HP Intelligent Management Center
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-89
8.8
2019-06-05 CVE-2019-11980 Improper Input Validation vulnerability in HP Intelligent Management Center
A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-20
8.8
2019-06-05 CVE-2019-11979 SQL Injection vulnerability in HP Intelligent Management Center
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-89
8.8