CSV
14,733 results for "vulnerability" Page 55
CVE-2017-12542 CRITICAL Exploit

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

Feb 15, 2018 1 affected product(s) NVD
10.0
CVSS
99.3%
EPSS
⚡ 79.8
CVE-2017-12557 CRITICAL Exploit

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
79.8%
EPSS
⚡ 73.1
CVE-2018-1161 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13. Authentication is not required to exploit this vulnerability. The specific flaw exists within nvwsworker.exe. When parsing the boundary header of a multipart request, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of SYSTEM. Was ZDI-CAN-4215.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
66.7%
EPSS
⚡ 59.2
CVE-2017-17420 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUJobCountHistory Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4231.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
48.2%
EPSS
⚡ 53.6
CVE-2017-12556 CRITICAL

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
37.9%
EPSS
⚡ 50.6
CVE-2017-12558 CRITICAL

A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
37.9%
EPSS
⚡ 50.6
CVE-2017-5792 CRITICAL

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

Feb 15, 2018 1 affected product(s) NVD
9.8
CVSS
34.3%
EPSS
⚡ 49.5
CVE-2017-12561 CRITICAL

A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
30.6%
EPSS
⚡ 48.4
CVE-2016-8519 CRITICAL

A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
27.6%
EPSS
⚡ 47.5
CVE-2017-5790 CRITICAL

A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

Feb 15, 2018 1 affected product(s) NVD
9.8
CVSS
18.0%
EPSS
⚡ 44.6
CVE-2018-1163 CRITICAL

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4752.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
16.0%
EPSS
⚡ 44
CVE-2016-8511 CRITICAL

A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.

Feb 15, 2018 12 affected product(s) NVD
9.8
CVSS
15.3%
EPSS
⚡ 43.8
CVE-2017-17417 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPhaseStatus Acknowledge method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4228.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
9.8%
EPSS
⚡ 42.1
CVE-2016-8512 CRITICAL

A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.

Feb 15, 2018 2 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.9
CVE-2018-3601 CRITICAL

A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.

Feb 9, 2018 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2017-17416 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPhaseStatus GetPlugins method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4227.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-17418 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPolicy Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4229.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-17419 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUTransferHistory Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4230.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-17421 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUSelectionSet Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4232.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-17422 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackup Get method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4233.

Feb 8, 2018 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4