CVE-2006-2574
published 2006-05-24CVE-2006-2574: Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via…
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.51%
40.3th percentile
Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjvr-x2w3-gr3m: Multiple unspecified vulnerabilities in Software Distributor in HP-UX B
ghsa_unreviewed·2022-05-01
CVE-2006-2574 [HIGH] GHSA-vjvr-x2w3-gr3m: Multiple unspecified vulnerabilities in Software Distributor in HP-UX B
Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.
GHSA
GHSA-44mf-wvvw-vrcw: Format string vulnerability in the swask command in HP-UX B
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2006-5558 [HIGH] GHSA-44mf-wvvw-vrcw: Format string vulnerability in the swask command in HP-UX B
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
GHSA
GHSA-frfv-fh86-whrq: Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2006-5557 [HIGH] GHSA-frfv-fh86-whrq: Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00659649http://secunia.com/advisories/20230http://secunia.com/advisories/20332http://securityreason.com/securityalert/964http://securitytracker.com/id?1016139http://support.avaya.com/elmodocs2/security/ASA-2006-106.htmhttp://www.securityfocus.com/archive/1/434838/100/0/threadedhttp://www.securityfocus.com/bid/18098http://www.vupen.com/english/advisories/2006/1947https://exchange.xforce.ibmcloud.com/vulnerabilities/26609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5568http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00659649http://secunia.com/advisories/20230http://secunia.com/advisories/20332http://securityreason.com/securityalert/964http://securitytracker.com/id?1016139http://support.avaya.com/elmodocs2/security/ASA-2006-106.htmhttp://www.securityfocus.com/archive/1/434838/100/0/threadedhttp://www.securityfocus.com/bid/18098http://www.vupen.com/english/advisories/2006/1947https://exchange.xforce.ibmcloud.com/vulnerabilities/26609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5568
2006-05-24
Published