Vulnerabilities > HP > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-31 CVE-2019-18913 Unspecified vulnerability in HP products
A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks.
low complexity
hp
6.8
2020-01-27 CVE-2019-19539 Insufficiently Protected Credentials vulnerability in HP products
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF.
local
low complexity
hp CWE-522
5.5
2020-01-27 CVE-2014-7301 Incorrect Default Permissions vulnerability in HP SGI Tempo
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
local
low complexity
hp CWE-276
6.6
2020-01-16 CVE-2019-11997 Cross-site Scripting vulnerability in HP Enhanced Internet Usage Manager 8.3/9.0
A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0.
network
low complexity
hp CWE-79
6.1
2020-01-09 CVE-2019-6332 Cross-site Scripting vulnerability in HP products
A potential security vulnerability has been identified with certain HP InkJet printers.
network
low complexity
hp CWE-79
4.8
2019-12-18 CVE-2019-11992 Cross-site Scripting vulnerability in HP Oneview for VMWare Vcenter 9.5
A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.
network
low complexity
hp CWE-79
6.1
2019-11-22 CVE-2019-18910 OS Command Injection vulnerability in HP Thinpro
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.
low complexity
hp CWE-78
6.8
2019-11-22 CVE-2019-16287 Unspecified vulnerability in HP Thinpro
In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker to executed commands with elevated privileges.
low complexity
hp
6.8
2019-11-22 CVE-2019-16286 Improper Authentication vulnerability in HP Thinpro Linux
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.
low complexity
hp CWE-287
6.8
2019-11-22 CVE-2019-16285 Information Exposure vulnerability in HP Thinpro Linux
If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.
low complexity
hp CWE-200
4.6