CVE-2015-3145
- EPSS 63.7%
- Veröffentlicht 24.04.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via...
- EPSS 3.01%
- Veröffentlicht 24.04.2015 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
CVE-2014-7874
- EPSS 0.16%
- Veröffentlicht 19.10.2014 01:55:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2014-2642
- EPSS 0.47%
- Veröffentlicht 02.10.2014 00:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
- EPSS 0.06%
- Veröffentlicht 02.10.2014 00:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVE-2014-2640
- EPSS 2.12%
- Veröffentlicht 02.10.2014 00:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6188
- EPSS 0.14%
- Veröffentlicht 14.03.2014 10:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- EPSS 0.65%
- Veröffentlicht 14.03.2014 10:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.
- EPSS 0.28%
- Veröffentlicht 23.09.2013 10:18:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors.
CVE-2013-2364
- EPSS 0.19%
- Veröffentlicht 22.07.2013 11:19:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.