Hp System Management Homepage vulnerabilities
77 known vulnerabilities affecting hp/system_management_homepage.
Total CVEs
77
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH14MEDIUM48LOW5
Vulnerabilities
Page 1 of 4
CVE-2015-3113P1CRITICALCVSS 9.8KEVPoCfixed in 7.5.02015-06-23
CVE-2015-3113 [CRITICAL] CWE-787 CVE-2015-3113: Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
nvd
CVE-2015-8651P1HIGHCVSS 8.8KEVRansomwarefixed in 7.62015-12-28
CVE-2015-8651 [HIGH] CWE-190 CVE-2015-8651: Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Wind
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-5388P2HIGHCVSS 8.1≤ 7.5.5.02016-07-19
CVE-2016-5388 [HIGH] CWE-284 CVE-2016-5388: Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy
nvd
CVE-2016-5385P2HIGHCVSS 8.1≤ 7.5.5.02016-07-19
CVE-2016-5385 [HIGH] CWE-601 CVE-2016-5385: PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and theref
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy hea
nvd
CVE-2016-5387P3HIGHCVSS 8.1≤ 7.5.5.02016-07-19
CVE-2016-5387 [HIGH] CVE-2016-5387: The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka
nvd
CVE-2016-1995P2CRITICALCVSS 9.8≤ 7.5.3.12016-03-18
CVE-2016-1995 [CRITICAL] CVE-2016-1995: HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via un
HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2011-1541P3CRITICALCVSS 10.0≤ 6.2.3.8v2.0.0+67 more2011-04-29
CVE-2011-1541 [CRITICAL] CVE-2011-1541: Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and consequently execute arbitrary code, via unknown vectors.
nvd
CVE-2015-3145P3HIGHCVSS 7.5≤ 7.5.3.12015-04-24
CVE-2015-3145 [HIGH] CWE-119 CVE-2015-3145: The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calcul
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
nvd
CVE-2017-12544P4MEDIUMCVSS 5.4PoCfixed in 7.6.12018-02-15
CVE-2017-12544 [MEDIUM] CWE-79 CVE-2017-12544: A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2011-1540P3CRITICALCVSS 9.0≤ 6.2.3.8v2.0.0+67 more2011-04-29
CVE-2011-1540 [CRITICAL] CVE-2011-1540: Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authentica
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authenticated users to execute arbitrary code via unknown vectors.
nvd
CVE-2016-4543P3CRITICALCVSS 9.8≤ 7.5.5.62016-05-22
CVE-2016-4543 [CRITICAL] CWE-119 CVE-2016-4543: The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21,
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
nvd
CVE-2012-2012P3CRITICALCVSS 10.0≤ 7.1.0-16v2.0.0+69 more2012-06-29
CVE-2012-2012 [CRITICAL] CVE-2012-2012: HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for uns
HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2015-4024P3MEDIUMCVSS 5.0≤ 7.5.3.12015-06-09
CVE-2015-4024 [MEDIUM] CWE-399 CVE-2015-4024: Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in P
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome.
nvd
CVE-2010-1586P4MEDIUMCVSS 4.3PoCv2.0.0v2.0.1+28 more2010-04-28
CVE-2010-1586 [MEDIUM] CWE-20 CVE-2010-1586: Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows re
Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.
nvd
CVE-2016-4396P3HIGHCVSS 7.5≤ 7.5.5.02016-10-28
CVE-2016-4396 [HIGH] CWE-119 CVE-2016-4396: HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
nvd
CVE-2016-4395P3HIGHCVSS 7.5≤ 7.5.5.02016-10-28
CVE-2016-4395 [HIGH] CWE-119 CVE-2016-4395: HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
nvd
CVE-2010-3009P3CRITICALCVSS 9.0v6.0v6.12010-09-15
CVE-2010-3009 [CRITICAL] CVE-2010-3009: Unspecified vulnerability in HP System Management Homepage (SMH) for Linux 6.0 and 6.1 allows remote
Unspecified vulnerability in HP System Management Homepage (SMH) for Linux 6.0 and 6.1 allows remote authenticated users to obtain sensitive information and gain root privileges via unknown vectors.
nvd
CVE-2015-3148P3MEDIUMCVSS 5.0≤ 7.5.3.12015-04-24
CVE-2015-3148 [MEDIUM] CWE-284 CVE-2015-3148: cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, w
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
nvd
CVE-2017-12545P3HIGHCVSS 7.5fixed in 7.6.12018-02-15
CVE-2017-12545 [HIGH] CWE-476 CVE-2017-12545: A remote denial of service vulnerability in HPE System Management Homepage for Windows and Linux ver
A remote denial of service vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
CVE-2023-50271P3HIGHCVSS 7.5fixed in a.3.2.23.092023-12-17
CVE-2023-50271 [HIGH] CWE-200 CVE-2023-50271: A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH).
A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.
nvd
1 / 4Next →