Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28
Vulnerabilities
Page 1 of 14
CVE-2012-1823P1CRITICALCVSS 9.8KEVPoCvb.11.23vb.11.312012-05-11
CVE-2012-1823 [CRITICAL] CWE-77 CVE-2012-1823: sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (ak
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for
nvd
CVE-2016-2776P1HIGHCVSS 7.5ExploitedPoCv11.312016-09-28
CVE-2016-2776 [HIGH] CWE-20 CVE-2016-2776: buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
nvd
CVE-2001-0797P2CRITICALCVSS 10.0ExploitedPoCv10.00v10.01+6 more2001-12-12
CVE-2001-0797 [CRITICAL] CVE-2001-0797: Buffer overflow in login in various System V based operating systems allows remote attackers to exec
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
nvd
CVE-2003-0201P2CRITICALCVSS 10.0ExploitedPoCv10.01v10.20+6 more2003-05-05
CVE-2003-0201 [CRITICAL] CVE-2003-0201: Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 an
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
nvd
CVE-1999-0502P2HIGHCVSS 7.5ExploitedPoCv10.20v111998-03-01
CVE-1999-0502 [HIGH] CVE-1999-0502: A Unix account has a default, null, blank, or missing password.
A Unix account has a default, null, blank, or missing password.
nvd
CVE-2003-0694P2CRITICALCVSS 10.0ExploitedPoCv11.00v11.0.4+2 more2003-10-06
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
nvd
CVE-2003-0681P2HIGHCVSS 7.5ExploitedPoCv11.00v11.0.4+2 more2003-10-06
CVE-2003-0681 [HIGH] CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rul
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
nvd
CVE-2013-4854P2HIGHCVSS 7.8Exploitedvb.11.312013-07-29
CVE-2013-4854 [HIGH] CVE-2013-4854: The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x b
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during c
nvd
CVE-2000-0573P2CRITICALCVSS 10.0PoCv11.002000-07-07
CVE-2000-0573 [CRITICAL] CVE-2000-0573: The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format strin
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
nvd
CVE-2002-1337P2CRITICALCVSS 10.0PoCv10.10v10.20+4 more2003-03-07
CVE-2002-1337 [CRITICAL] CWE-120 CVE-2002-1337: Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via cer
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
nvd
CVE-2015-4000P3LOWCVSS 3.7PoCvb.11.312015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2005-3277P3CRITICALCVSS 10.0PoCv10.20v11.00+1 more2005-10-21
CVE-2005-3277 [CRITICAL] CVE-2005-3277: The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
nvd
CVE-2004-1029P3CRITICALCVSS 9.3PoCv11.00v11.11+2 more2005-03-01
CVE-2004-1029 [CRITICAL] CWE-264 CVE-2004-1029: The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
nvd
CVE-1999-0046P3CRITICALCVSS 10.0PoCv10.00v10.01+8 more1997-02-06
CVE-1999-0046 [CRITICAL] CWE-120 CVE-1999-0046: Buffer overflow of rlogin program using TERM environmental variable.
Buffer overflow of rlogin program using TERM environmental variable.
nvd
CVE-2004-0594P3MEDIUMCVSS 5.1PoCvb.11.00vb.11.11+2 more2004-07-27
CVE-2004-0594 [MEDIUM] CWE-367 CVE-2004-0594: The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditi
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization o
nvd
CVE-2003-0161P3CRITICALCVSS 10.0PoCv10.00v10.01+14 more2003-04-02
CVE-2003-0161 [CRITICAL] CVE-2003-0161: The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not proper
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary
nvd
CVE-1999-0003P3CRITICALCVSS 10.0PoCv10.01v10.02+2 more1998-04-01
CVE-1999-0003 [CRITICAL] CVE-1999-0003: Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
nvd
CVE-2006-5558P3CRITICALCVSS 10.0PoCv11.00v11.4+2 more2006-10-27
CVE-2006-5558 [CRITICAL] CVE-2006-5558: Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
nvd
CVE-2002-1317P3HIGHCVSS 7.5PoCv10.10v10.20+5 more2002-12-11
CVE-2002-1317 [HIGH] CVE-2002-1317: Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allow
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
nvd
CVE-2000-0699P3CRITICALCVSS 10.0PoCv10.20v11.002000-10-20
CVE-2000-0699 [CRITICAL] CVE-2000-0699: Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of serv
Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.
nvd
1 / 14Next →