Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28
Vulnerabilities
Page 12 of 14
CVE-2006-1509P4MEDIUMCVSS 4.9v11.00v11.11+1 more2006-03-30
CVE-2006-1509 [MEDIUM] CVE-2006-1509: /sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully fro
/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.
nvd
CVE-1999-0432P4MEDIUMCVSS 4.6v11.001999-03-01
CVE-1999-0432 [MEDIUM] CVE-1999-0432: ftp on HP-UX 11.00 allows local users to gain privileges.
ftp on HP-UX 11.00 allows local users to gain privileges.
nvd
CVE-1999-0436P4MEDIUMCVSS 4.6v10.20v11.001999-03-01
CVE-1999-0436 [MEDIUM] CVE-1999-0436: Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
nvd
CVE-2001-1509P4MEDIUMCVSS 4.6v11.202001-12-31
CVE-2001-1509 [MEDIUM] CVE-2001-1509: geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effe
geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.
nvd
CVE-1999-1242P4MEDIUMCVSS 4.6v9.00v9.011994-02-07
CVE-1999-1242 [MEDIUM] CVE-1999-1242: Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.
Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.
nvd
CVE-1999-1248P4MEDIUMCVSS 4.6≤ 9.00v8.00+2 more1994-11-30
CVE-1999-1248 [MEDIUM] CVE-1999-1248: Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gai
Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.
nvd
CVE-1999-1213P4MEDIUMCVSS 5.0v10.301997-10-01
CVE-1999-1213 [MEDIUM] CVE-1999-1213: Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.
Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.
nvd
CVE-2006-3097P4MEDIUMCVSS 4.9v11.11v11.232006-06-20
CVE-2006-3097 [MEDIUM] CVE-2006-3097: Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.2
Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
nvd
CVE-2006-3201P4MEDIUMCVSS 4.9v11.00v11.11+1 more2006-06-23
CVE-2006-3201 [MEDIUM] CVE-2006-3201: Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to
Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
nvd
CVE-1999-0308P4MEDIUMCVSS 4.6v8v91996-10-01
CVE-1999-0308 [MEDIUM] CVE-1999-0308: HP-UX gwind program allows users to modify arbitrary files.
HP-UX gwind program allows users to modify arbitrary files.
nvd
CVE-1999-1308P4MEDIUMCVSS 4.6v10.201997-07-31
CVE-1999-1308 [MEDIUM] CVE-1999-1308: Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
nvd
CVE-2000-0414P4MEDIUMCVSS 4.6v10.10v10.20+1 more2000-05-04
CVE-2000-0414 [MEDIUM] CVE-2000-0414: Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileg
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
nvd
CVE-1999-1249P4MEDIUMCVSS 4.6v10.201997-01-06
CVE-1999-1249 [MEDIUM] CVE-1999-1249: movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.
movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.
nvd
CVE-2004-2753P4MEDIUMCVSS 5.6v11.00v11.11+1 more2004-12-31
CVE-2004-2753 [MEDIUM] CVE-2004-2753: Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to ac
Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of "files in a potentially insecure manner."
nvd
CVE-2007-0916P4MEDIUMCVSS 4.9v11.11v11.232007-02-14
CVE-2007-0916 [MEDIUM] CVE-2007-0916: Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality i
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
nvd
CVE-2007-1994P4MEDIUMCVSS 4.9v11.002007-04-12
CVE-2007-1994 [MEDIUM] CVE-2007-1994: Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality i
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.
nvd
CVE-2001-0772P4MEDIUMCVSS 4.6≤ 11.11v10.102001-10-18
CVE-2001-0772 [MEDIUM] CVE-2001-0772: Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in H
Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.
nvd
CVE-2001-0607P4MEDIUMCVSS 4.6≤ 11.002001-08-22
CVE-2001-0607 [MEDIUM] CVE-2001-0607: asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of
asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.
nvd
CVE-1999-1133P4MEDIUMCVSS 4.6v9v101997-09-01
CVE-1999-1133 [MEDIUM] CVE-1999-1133: HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.
nvd
CVE-1999-1238P4MEDIUMCVSS 4.6≤ 9.05v8+1 more1994-09-21
CVE-1999-1238 [MEDIUM] CVE-1999-1238: Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local user
Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.
nvd