Vulnerabilities > HP > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-09-08 CVE-2016-4380 Cross-site Scripting vulnerability in HP Operations Manager 9.21
Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hp CWE-79
5.4
2016-07-19 CVE-2016-2775 Improper Input Validation vulnerability in multiple products
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
network
high complexity
hp isc fedoraproject redhat CWE-20
5.9
2016-06-08 CVE-2016-4363 Cross-site Scripting vulnerability in HP Insight Control Server Deployment
HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.
network
low complexity
hp CWE-79
6.1
2016-05-30 CVE-2016-2023 Information Exposure vulnerability in HP Restful Interface Tool 1.40
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
hp CWE-200
5.5
2016-05-14 CVE-2016-2016 Improper Access Control vulnerability in HP Base-Vxfs-50, Base-Vxfs-501 and Base-Vxfs-51
Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.
local
low complexity
hp CWE-284
5.5
2016-05-07 CVE-2016-2013 Information Exposure vulnerability in HP Network Node Manager I
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
hp CWE-200
6.5
2016-05-07 CVE-2016-2012 Improper Authentication vulnerability in HP Network Node Manager I
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.
network
low complexity
hp CWE-287
6.5
2016-05-07 CVE-2016-2011 Cross-site Scripting vulnerability in HP Network Node Manager I
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
network
low complexity
hp CWE-79
5.4
2016-05-07 CVE-2016-2010 Cross-site Scripting vulnerability in HP Network Node Manager I
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.
network
low complexity
hp CWE-79
5.4
2016-05-05 CVE-2016-2107 Information Exposure vulnerability in multiple products
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session.
5.9