Vulnerabilities > HP > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-11135 TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. 6.5
2019-11-07 CVE-2019-6337 Unspecified vulnerability in HP products
For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert.
low complexity
hp
5.2
2019-10-11 CVE-2019-6333 Uncontrolled Search Path Element vulnerability in HP Touchpoint Analytics
A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827.
local
low complexity
hp CWE-427
6.7
2019-10-04 CVE-2019-11656 Cross-site Scripting vulnerability in HP Arcsight Logger
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0.
network
low complexity
hp CWE-79
5.4
2019-08-09 CVE-2019-5408 Unspecified vulnerability in HP products
Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server.
network
low complexity
hp
6.5
2019-08-09 CVE-2019-5407 Unspecified vulnerability in HP 3Par Storeserv Management Console 3.3.1/3.5
A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
network
low complexity
hp
6.3
2019-08-09 CVE-2019-5403 Cross-site Scripting vulnerability in HP 3Par Storeserv Management Console 3.3.1/3.5
A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
network
low complexity
hp CWE-79
4.8
2019-08-09 CVE-2019-5400 Session Fixation vulnerability in HP 3Par Service Processor Firmware
A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
network
low complexity
hp CWE-384
6.3
2019-08-09 CVE-2019-5398 Cross-site Scripting vulnerability in HP 3Par Service Processor Firmware
A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
network
low complexity
hp CWE-79
5.4
2019-08-01 CVE-2019-5401 Cross-site Scripting vulnerability in HP Hp2910Al-48G Firmware W.15.14.00.16
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016.
network
low complexity
hp CWE-79
4.8