cbcvebase.

Hp System Management Homepage vulnerabilities

77 known vulnerabilities affecting hp/system_management_homepage.

Total CVEs
77
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH14MEDIUM48LOW5

Vulnerabilities

Page 2 of 4
CVE-2016-1993P3HIGHCVSS 8.1≤ 7.5.3.12016-03-18
CVE-2016-1993 [HIGH] CVE-2016-1993: HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive in HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
nvd
CVE-2007-3260P3CRITICALCVSS 9.0≤ 2.1.82007-06-19
CVE-2007-3260 [CRITICAL] CVE-2007-3260: HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assign HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assigns the eDirectory members to the root group, which allows remote authenticated eDirectory users to gain privileges.
nvd
CVE-2012-2014P3CRITICALCVSS 9.0≤ 7.1.0-16v2.0.0+69 more2012-06-29
CVE-2012-2014 [CRITICAL] CVE-2012-2014: HP System Management Homepage (SMH) before 7.1.1 does not properly validate input, which allows remo HP System Management Homepage (SMH) before 7.1.1 does not properly validate input, which allows remote authenticated users to have an unspecified impact via unknown vectors.
nvd
CVE-2006-1774P3HIGHCVSS 7.5v2.1.3.1322006-04-13
CVE-2006-1774 [HIGH] CVE-2006-1774: HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linu HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
nvd
CVE-2012-2015P3CRITICALCVSS 9.0≤ 7.1.0-16v2.0.0+69 more2012-06-29
CVE-2012-2015 [CRITICAL] CVE-2012-2015: Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote authenti Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote authenticated users to gain privileges and obtain sensitive information via unknown vectors.
nvd
CVE-2015-3143P3MEDIUMCVSS 5.0≤ 7.5.3.12015-04-24
CVE-2015-3143 [MEDIUM] CVE-2015-3143: cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remot cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
nvd
CVE-2015-3237P4MEDIUMCVSS 6.4≤ 7.5.3.12015-06-22
CVE-2015-3237 [MEDIUM] CWE-20 CVE-2015-3237: The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers t The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
nvd
CVE-2012-2013P4HIGHCVSS 7.5≤ 7.1.0-16v2.0.0+69 more2012-06-29
CVE-2012-2013 [HIGH] CVE-2012-2013: Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attacker Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain sensitive information or modify data, via unknown vectors.
nvd
CVE-2016-1996P4HIGHCVSS 7.7≤ 7.5.3.12016-03-18
CVE-2016-1996 [HIGH] CVE-2016-1996: HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or mo HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors.
nvd
CVE-2016-1994P4MEDIUMCVSS 6.5≤ 7.5.3.12016-03-18
CVE-2016-1994 [MEDIUM] CWE-200 CVE-2016-1994: HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive in HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2006-1023P4MEDIUMCVSS 5.0v2.0.0v2.1.42006-03-07
CVE-2006-1023 [MEDIUM] CVE-2006-1023: Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Wind Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.
nvd
CVE-2016-4394P4MEDIUMCVSS 6.5≤ 7.5.5.02016-10-28
CVE-2016-4394 [MEDIUM] CWE-254 CVE-2016-4394: HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information v HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.
nvd
CVE-2014-7874P4MEDIUMCVSS 6.8≤ 3.2.2≤ 3.2.72014-10-19
CVE-2014-7874 [MEDIUM] CWE-352 CVE-2014-7874: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2016-2015P4HIGHCVSS 7.1≤ 7.5.4.32016-05-14
CVE-2016-2015 [HIGH] CWE-200 CVE-2016-2015: HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or mo HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.
nvd
CVE-2012-5217P4MEDIUMCVSS 5.0≤ 7.2v7.0+1 more2013-07-22
CVE-2012-5217 [MEDIUM] CWE-264 CVE-2012-5217: HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access r HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-2355.
nvd
CVE-2013-2355P4MEDIUMCVSS 5.0≤ 7.2v7.0+1 more2013-07-22
CVE-2013-2355 [MEDIUM] CVE-2013-2355: HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access r HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2012-5217.
nvd
CVE-2011-3846P4MEDIUMCVSS 6.8v6.2.2.72012-04-12
CVE-2011-3846 [MEDIUM] CWE-352 CVE-2011-3846: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allow Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
nvd
CVE-2010-3011P4MEDIUMCVSS 5.0≤ 6.1v2.0.0+58 more2010-09-17
CVE-2010-3011 [MEDIUM] CWE-20 CVE-2010-3011: CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attacke CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2013-6188P4MEDIUMCVSS 6.8v7.1v7.2+2 more2014-03-14
CVE-2013-6188 [MEDIUM] CWE-352 CVE-2013-6188: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7 Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2017-12551P4MEDIUMCVSS 5.6fixed in 7.6.12018-02-15
CVE-2017-12551 [MEDIUM] CVE-2017-12551: A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
nvd
Hp System Management Homepage vulnerabilities | cvebase