Category Archives: Checkpoint

Checkpoint

HPE Data Protector EXEC_BAR domain Buffer Overflow (CVE-2016-2006)

A buffer overflow vulnerability has been found in the Omnilnet.exe component of HPE Data Protector. This vulnerability is due to lack of boundary checks on the domain field in EXEC_BAR requests. A remote, unauthenticated attacker could exploit this vulnerability by sending malformed requests to a HPE Data Protector service potentially leading to arbitrary code execution under the context of System.

Cisco Prime Infrastructure and EPNM Deserialization Code Execution (CVE-2016-1291)

A vulnerability has been found in the web interface of Cisco Prime Infrastructure and Evolved programmable Network Manager (EPNM). The vulnerability is due to insufficient sanitization of user supplied input to the web interface. A remote, unauthenticated attacker could exploit this vulnerability by sending an HTTP POST request with maliciously crafted serialized user data.