Unknown · CVSS Not scored
HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability in HGLM version HGLM 6.3.0-00 to 8.5.2-00.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not safe. The severity of this issue is high due to the fact that the build scripts immediately start a build after Gradle has been fetched. Developers who are concerned about this issue should install version 6.1.2 or higher of Cordova-Android. If developers are unable to install the latest version, this vulnerability can easily be mitigated by setting the CORDOVA_ANDROID_GRADLE_DISTRIBUTION_URL environment variable to https://services.gradle.org/distributions/gradle-2.14.1-all.zip
Published Feb 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134004.
Published Feb 14, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
Published Feb 27, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.
Published Feb 23, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sending crafted Router Advertisement (RA) messages to a targeted system.
Published Feb 8, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
Published Feb 14, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
Published Feb 14, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
Published Feb 12, 2019 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68159767.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.
Published Feb 23, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.
Published Feb 15, 2018 · Updated Sep 16, 2024