CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-12535

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12536

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12537

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12539

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12540

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12541

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Published: 15 Feb 2018
    10
    Critical

    CVE-2017-12542

    Last Modified: 21 Nov 2024

    A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2017-12544

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12546

    Last Modified: 21 Nov 2024

    A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12547

    Last Modified: 21 Nov 2024

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12548

    Last Modified: 21 Nov 2024

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12549

    Last Modified: 21 Nov 2024

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12550

    Last Modified: 21 Nov 2024

    A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    5.6
    Medium

    CVE-2017-12551

    Last Modified: 21 Nov 2024

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-12554

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT iMC Plat 7.3 E0504P2 and earlier was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-12555

    Last Modified: 21 Nov 2024

    A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-12556

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-12557

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-12558

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-12559

    Last Modified: 21 Nov 2024

    A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2017-8949

    Last Modified: 21 Nov 2024

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8959

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability in HPE MSA 1040 and HPE MSA 2040 SAN Storage in version GL220P008 and earlier and was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8966

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8967

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8975

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8979

    Last Modified: 21 Nov 2024

    Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8984

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2017-5782

    Last Modified: 21 Nov 2024

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

    Published: 15 Feb 2018
    5.3
    Medium

    CVE-2017-5783

    Last Modified: 21 Nov 2024

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-5784

    Last Modified: 21 Nov 2024

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-5785

    Last Modified: 21 Nov 2024

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-5787

    Last Modified: 21 Nov 2024

    A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5790

    Last Modified: 21 Nov 2024

    A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5792

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-5793

    Last Modified: 21 Nov 2024

    A Remote Arbitrary Code Execution vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-5794

    Last Modified: 21 Nov 2024

    A Remote Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

    Published: 15 Feb 2018
    6.5
    Medium

    CVE-2017-5795

    Last Modified: 21 Nov 2024

    A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5802

    Last Modified: 19 Nov 2025

    A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.

    Published: 15 Feb 2018
    6.1
    Medium

    CVE-2017-5798

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-5799

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2017-5800

    Last Modified: 21 Nov 2024

    A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-5801

    Last Modified: 21 Nov 2024

    A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2018-7174

    Last Modified: 21 Nov 2024

    An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2018-7175

    Last Modified: 21 Nov 2024

    An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2014-0014

    Last Modified: 21 Nov 2024

    Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2014-0013

    Last Modified: 21 Nov 2024

    Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a user-supplied primitive value and also contain the `{{this}}` special Handlebars variable.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2018-7173

    Last Modified: 21 Nov 2024

    A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2017-15340

    Last Modified: 21 Nov 2024

    Huawei smartphones with software of TAG-AL00C92B168 have an information disclosure vulnerability. An attacker tricks the user to install a crafted application, this application simulate click action to back up data in a non-encrypted way using an Android assist function. Successful exploit could result in information disclosure.

    Published: 15 Feb 2018
    5.3
    Medium

    CVE-2017-15334

    Last Modified: 21 Nov 2024

    The SIP backup feature in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6800 V500R001C50, RP200 V500R002C00, V600R006C00, SVN5600 V200R003C00, V200R003C10, SVN5800 V200R003C00, V200R003C10, SVN5800-C V200R003C00, V200R003C10, SeMG9811 V300R001C01, Secospace USG6300 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V100R001C00, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, TE30 V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002C00, V600R006C00, USG9500 V500R001C00, V500R001C20, V500R001C30, USG9520 V300R001C01, V300R001C20, USG9560 V300R001C01, V300R001C20, USG9580 V300R001C01, V300R001C20, VP9660 V200R001C02, V200R001C30, V500R002C00, V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02, V100R011C03, eSpace U1981 V100R001C20, V200R003C00, V200R003C20, V200R003C30 has a buffer overflow vulnerability. An attacker may send specially crafted messages to the affected products. Due to the insufficient validation of some values for SIP messages, successful exploit may cause services abnormal.

    Published: 15 Feb 2018
    3.7
    Low

    CVE-2017-15338

    Last Modified: 21 Nov 2024

    The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6800 V500R001C50, RP200 V500R002C00, V600R006C00, SVN5600 V200R003C00, V200R003C10, SVN5800 V200R003C00, V200R003C10, SVN5800-C V200R003C00, V200R003C10, SeMG9811 V300R001C01, Secospace USG6300 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V100R001C00, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, TE30 V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002C00, V600R006C00, USG9500 V500R001C00, V500R001C20, V500R001C30, USG9520 V300R001C01, V300R001C20, USG9560 V300R001C01, V300R001C20, USG9580 V300R001C01, V300R001C20, VP9660 V200R001C02, V200R001C30, V500R002C00, V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02, V100R011C03, eSpace U1981 V100R001C20, V200R003C00, V200R003C20, V200R003C30 has a buffer overflow vulnerability. An attacker would have to find a way to craft specific messages to the affected products. Due to the insufficient validation for SIP messages, successful exploit may cause services abnormal.

    Published: 15 Feb 2018