|
265261
|
9.8 |
CRITICAL
Network
|
hp
|
keyview
|
A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4402
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265262
|
5.4 |
MEDIUM
Network
|
hp
|
network_node_manager_i
|
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2016-4400
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265263
|
5.4 |
MEDIUM
Network
|
hp
|
network_node_manager_i
|
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2016-4399
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265264
|
8.8 |
HIGH
Network
|
hp
|
network_node_manager_i
|
A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-4398
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265265
|
7.8 |
HIGH
Local
|
hp
|
network_node_manager_i
|
A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.
|
CWE-94
Code Injection
|
CVE-2016-4397
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265266
|
5.4 |
MEDIUM
Network
|
hp
|
business_service_management
|
A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4392
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265267
|
9.8 |
CRITICAL
Network
|
hp
|
arcsight_winc_connector
|
A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.
|
CWE-94
Code Injection
|
CVE-2016-4391
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265268
|
8.8 |
HIGH
Network
|
apache netapp
|
struts oncommand_balance
|
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because …
|
CWE-20
Improper Input Validation
|
CVE-2016-4461
|
2024-11-21 11:52 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265269
|
7.8 |
HIGH
Local
|
apache
|
tika
|
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) sprea…
|
CWE-611
XXE
|
CVE-2016-4434
|
2024-11-21 11:52 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265270
|
8.8 |
HIGH
Network
|
apache
|
ofbiz
|
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Fr…
|
CWE-20
Improper Input Validation
|
CVE-2016-4462
|
2024-11-21 11:52 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|