VendorsHPloadrunnerall versions
Vulnerabilities

HP Loadrunner

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2010-1549
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.
Published 2010-05-07 · Modified
10.01 PoCEPSS 0.776
CVE-2013-4798
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.
Published 2013-07-26 · Modified
10.01 PoCEPSS 0.670
CVE-2013-4837
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.
Published 2013-11-04 · Modified
10.01 PoCEPSS 0.626
CVE-2011-0272
Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.
Published 2011-01-18 · Modified
10.0EPSS 0.134
CVE-2015-2110
Buffer overflow in HP LoadRunner 11.52 allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2015-05-25 · Modified
10.0EPSS 0.108
CVE-2013-4838
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1850.
Published 2013-11-04 · Modified
10.0EPSS 0.107
CVE-2013-6213
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833.
Published 2014-04-19 · Modified
10.0EPSS 0.105
CVE-2017-5789
HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow.
Published 2017-10-13 · Modified
9.8EPSS 0.179
CVE-2016-4359
Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.
Published 2016-06-08 · Modified
9.8EPSS 0.158
CVE-2016-8512
A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.
Published 2018-02-15 · Modified
9.8EPSS 0.055
CVE-2009-3693
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
Published 2009-10-13 · Modified
9.32 PoCEPSS 0.416
CVE-2013-4800
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735.
Published 2013-07-26 · Modified
9.31 PoCEPSS 0.393
CVE-2007-6530
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
Published 2007-12-27 · Modified
9.32 PoCEPSS 0.368
CVE-2016-4360
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.
Published 2016-06-08 · Modified
9.1EPSS 0.086
CVE-2016-4384
HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.
Published 2016-09-21 · Modified
9.0EPSS 0.036
CVE-2013-4799
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1734.
Published 2013-07-26 · Modified
7.6EPSS 0.082
CVE-2013-2370
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.
Published 2013-07-26 · Modified
7.51 PoCEPSS 0.619
CVE-2013-4801
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1736.
Published 2013-07-26 · Modified
7.5EPSS 0.081
CVE-2016-4361
HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow remote attackers to cause a denial of service via unspecified vectors.
Published 2016-06-08 · Modified
7.5EPSS 0.076
CVE-2013-4797
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1690.
Published 2013-07-26 · Modified
7.5EPSS 0.063
CVE-2013-2369
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1670.
Published 2013-07-26 · Modified
7.5EPSS 0.055
CVE-2013-4839
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1851.
Published 2013-11-04 · Modified
7.5EPSS 0.040
CVE-2010-4028
Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors.
Published 2010-10-28 · Modified
7.5EPSS 0.023
CVE-2015-6857
Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-3138.
Published 2015-11-26 · Modified
7.2EPSS 0.038
CVE-2011-2328
Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives.
Published 2011-06-02 · Modified
6.8EPSS 0.059
CVE-2017-8953
A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.
Published 2018-02-15 · Modified
5.4EPSS 0.008
CVE-2013-2368
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to cause a denial of service via unknown vectors, aka ZDI-CAN-1669.
Published 2013-07-26 · Modified
5.0EPSS 0.096
CVE-2015-5426
Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.
Published 2015-09-16 · Modified
4.6EPSS 0.008