Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
2
Severity breakdown
CRITICAL42HIGH109MEDIUM96LOW28
Vulnerabilities
Page 11 of 14
CVE-2000-0573CRITICALCVSS 10.0PoCv11.002000-07-07
CVE-2000-0573 [CRITICAL] CVE-2000-0573: The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format strin
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
nvd
CVE-2000-0515CRITICALCVSS 10.0PoCv10.20v11.002000-06-07
CVE-2000-0515 [CRITICAL] CVE-2000-0515: The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which
The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.
nvd
CVE-2000-0468MEDIUMCVSS 4.6PoCv10.20v11.002000-06-02
CVE-2000-0468 [MEDIUM] CVE-2000-0468: man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
nvd
CVE-2000-0414MEDIUMCVSS 4.6v10.10v10.20+1 more2000-05-04
CVE-2000-0414 [MEDIUM] CVE-2000-0414: Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileg
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
nvd
CVE-2000-0083MEDIUMCVSS 4.6v10v112000-04-18
CVE-2000-0083 [MEDIUM] CVE-2000-0083: HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local u
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
nvd
CVE-2000-0251MEDIUMCVSS 5.0v11.42000-04-06
CVE-2000-0251 [MEDIUM] CVE-2000-0251: HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multi
HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.
nvd
CVE-1999-0693HIGHCVSS 7.2PoCv10v112000-03-02
CVE-1999-0693 [HIGH] CVE-1999-0693: Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
nvd
CVE-2000-0159HIGHCVSS 7.5v11.002000-02-17
CVE-2000-0159 [HIGH] CVE-2000-0159: HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set t
HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.
nvd
CVE-2000-0095MEDIUMCVSS 5.0v10.30v11.002000-01-24
CVE-2000-0095 [MEDIUM] CVE-2000-0095: The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates
The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.
nvd
CVE-2000-0078HIGHCVSS 7.2v10v112000-01-02
CVE-2000-0078 [HIGH] CVE-2000-0078: The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifyi
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.
nvd
CVE-2000-0077HIGHCVSS 7.2PoCv10v112000-01-02
CVE-2000-0077 [HIGH] CVE-2000-0077: The October 1998 version of the HP-UX aserver program allows local users to gain privileges by speci
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.
nvd
CVE-1999-1573CRITICALCVSS 10.0v10.00v10.01+4 more1999-12-28
CVE-1999-1573 [CRITICAL] CVE-1999-1573: Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (
Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.
nvd
CVE-1999-0696CRITICALCVSS 10.0PoCv10.24v11.001999-07-01
CVE-1999-0696 [CRITICAL] CVE-1999-0696: Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
nvd
CVE-1999-0707HIGHCVSS 7.5v10.201999-07-01
CVE-1999-0707 [HIGH] CVE-1999-0707: The default FTP configuration in HP Visualize Conference allows conference users to send a file to o
The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.
nvd
CVE-1999-0690HIGHCVSS 7.2v101999-07-01
CVE-1999-0690 [HIGH] CVE-1999-0690: HP CDE program includes the current directory in root's PATH variable.
HP CDE program includes the current directory in root's PATH variable.
nvd
CVE-1999-0688MEDIUMCVSS 4.6v10.24v11.001999-07-01
CVE-1999-0688 [MEDIUM] CVE-1999-0688: Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
nvd
CVE-1999-0686MEDIUMCVSS 5.0v10.241999-05-07
CVE-1999-0686 [MEDIUM] CVE-1999-0686: Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
nvd
CVE-1999-0435HIGHCVSS 7.2v10.00v10.01+2 more1999-03-01
CVE-1999-0435 [HIGH] CVE-1999-0435: MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
nvd
CVE-1999-0479MEDIUMCVSS 5.0v10.241999-03-01
CVE-1999-0479 [MEDIUM] CVE-1999-0479: Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.
Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.
nvd
CVE-1999-0432MEDIUMCVSS 4.6v11.001999-03-01
CVE-1999-0432 [MEDIUM] CVE-1999-0432: ftp on HP-UX 11.00 allows local users to gain privileges.
ftp on HP-UX 11.00 allows local users to gain privileges.
nvd