Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2016
HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.017
Published
2016-06-08
HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.
CVSS Score
8.4
EPSS Score
0.003
Published
2016-06-08
HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.
CVSS Score
6.1
EPSS Score
0.01
Published
2016-06-08
HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
CVSS Score
8.1
EPSS Score
0.002
Published
2016-06-08
HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow remote attackers to cause a denial of service via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.03
Published
2016-06-08
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.
CVSS Score
9.1
EPSS Score
0.061
Published
2016-06-08
Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.
CVSS Score
9.8
EPSS Score
0.304
Published
2016-06-08
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2029.
CVSS Score
8.1
EPSS Score
0.01
Published
2016-06-08
HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028.
CVSS Score
8.1
EPSS Score
0.002
Published
2016-06-08
Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2016-06-08


Contact Us

Shodan ® - All rights reserved