Vulnerabilities > HP > High

DATE CVE VULNERABILITY TITLE RISK
2011-08-01 CVE-2011-2399 Denial of Service vulnerability in HP OpenView Storage Data Protector 6.10/6.11
Unspecified vulnerability in the Media Management Daemon (mmd) in HP Data Protector 6.11 and earlier allows remote attackers to cause a denial of service via unknown vectors.
network
low complexity
hp
7.8
2011-07-29 CVE-2011-2401 Session Fixation vulnerability in HP SiteScope
Session fixation vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to hijack web sessions via unspecified vectors.
network
hp
8.3
2011-06-14 CVE-2011-1863 Code Injection vulnerability in HP Service Center and Service Manager
HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors.
network
hp CWE-94
7.5
2011-06-14 CVE-2011-1861 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.
network
hp
8.3
2011-06-14 CVE-2011-1857 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.
network
hp
8.2
2011-05-13 CVE-2011-1738 Permissions, Privileges, and Access Controls vulnerability in HP Palm Webos 1.4.5/1.4.5.1
HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.
local
low complexity
hp CWE-264
7.2
2011-05-07 CVE-2011-1736 Path Traversal vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Directory traversal vulnerability in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to read arbitrary files via directory traversal sequences in a filename in a GET_FILE message.
network
low complexity
hp CWE-22
8.5
2011-04-15 CVE-2011-1532 Multiple Security vulnerability in HP Photosmart Printers
Unspecified vulnerability in the SNMP component on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to obtain sensitive information or modify data via vectors related to the Embedded Web Server (EWS).
network
low complexity
hp
7.5
2011-01-28 CVE-2011-0275 Denial of Service vulnerability in HP OpenView Storage Data Protector 6.0/6.10/6.11
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.
network
hp
7.1
2011-01-20 CVE-2010-4267 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Linux Imaging and Printing Project 1.6.7/3.10.9/3.9.8
Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.
network
low complexity
hp CWE-119
7.5