Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28
Vulnerabilities
Page 3 of 14
CVE-2001-0311P4MEDIUMCVSS 4.6PoC≤ 112001-06-02
CVE-2001-0311 [MEDIUM] CVE-2001-0311: Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized acc
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.
nvd
CVE-2003-0840P4HIGHCVSS 7.2PoCv11.002003-11-17
CVE-2003-0840 [HIGH] CVE-2003-0840: Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local us
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.
nvd
CVE-2004-0826P3HIGHCVSS 7.5v11.00v11.11+1 more2004-12-31
CVE-2004-0826 [HIGH] CVE-2004-0826: Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attacke
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
nvd
CVE-2001-0817P3CRITICALCVSS 10.0v10.01v10.10+3 more2001-12-06
CVE-2001-0817 [CRITICAL] CVE-2001-0817: Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote at
Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.
nvd
CVE-2006-5151P3CRITICALCVSS 10.0v11.00v11.11+1 more2006-10-05
CVE-2006-5151 [CRITICAL] CVE-2006-5151: Unspecified vulnerability in HP Ignite-UX server before C.6.9.150 for HP-UX B.11.00, B.11.11, and B.
Unspecified vulnerability in HP Ignite-UX server before C.6.9.150 for HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to "gain root access" via unspecified vectors.
nvd
CVE-2007-1993P3CRITICALCVSS 9.3vb.11.00vb.11.11+1 more2007-04-12
CVE-2007-1993 [CRITICAL] CWE-119 CVE-2007-1993: Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00,
Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."
nvd
CVE-2003-1461P4HIGHCVSS 7.2PoCv11.002003-12-31
CVE-2003-1461 [HIGH] CVE-2003-1461: Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a lon
Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).
nvd
CVE-2007-5008P3CRITICALCVSS 9.0v11.11v11.23+1 more2007-09-20
CVE-2007-5008 [CRITICAL] CWE-287 CVE-2007-5008: The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status,
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
nvd
CVE-2004-0716P3CRITICALCVSS 10.0v112004-08-06
CVE-2004-0716 [CRITICAL] CVE-2004-0716: Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remo
Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.
nvd
CVE-2001-0979P4HIGHCVSS 7.2PoCv10.01v10.10+2 more2001-09-03
CVE-2001-0979 [HIGH] CVE-2001-0979: Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain p
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.
nvd
CVE-2003-1359P4HIGHCVSS 7.2PoCv10.00v10.01+15 more2003-12-31
CVE-2003-1359 [HIGH] CWE-119 CVE-2003-1359: Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privilege
Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.
nvd
CVE-1999-0130P4HIGHCVSS 7.2PoCv10.00v10.01+2 more1996-11-16
CVE-1999-0130 [HIGH] CVE-1999-0130: Local users can start Sendmail in daemon mode and gain root privileges.
Local users can start Sendmail in daemon mode and gain root privileges.
nvd
CVE-2000-0077P4HIGHCVSS 7.2PoCv10v112000-01-02
CVE-2000-0077 [HIGH] CVE-2000-0077: The October 1998 version of the HP-UX aserver program allows local users to gain privileges by speci
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.
nvd
CVE-2002-1473P4MEDIUMCVSS 4.6PoCv10.20v11.00+1 more2003-04-22
CVE-2002-1473 [MEDIUM] CVE-2002-1473: Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to c
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2012-0131P3CRITICALCVSS 10.0vb.11.11vb.11.232012-04-05
CVE-2012-0131 [CRITICAL] CVE-2012-0131: Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote at
Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2002-1614P4HIGHCVSS 7.2PoCv10.20v11.00+3 more2002-09-09
CVE-2002-1614 [HIGH] CVE-2002-1614: Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to
Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.
nvd
CVE-1999-0040P4HIGHCVSS 7.2PoCv9.00v9.01+11 more1997-05-01
CVE-1999-0040 [HIGH] CVE-1999-0040: Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
nvd
CVE-1999-0693P4HIGHCVSS 7.2PoCv10v112000-03-02
CVE-1999-0693 [HIGH] CVE-1999-0693: Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
nvd
CVE-2003-1358P4HIGHCVSS 7.2PoCv10.00v10.01+15 more2003-12-31
CVE-2003-1358 [HIGH] CWE-264 CVE-2003-1358: rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
nvd
CVE-1999-0038P4HIGHCVSS 8.4PoCv10.00v10.01+7 more1997-04-26
CVE-1999-0038 [HIGH] CWE-120 CVE-1999-0038: Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in xlock program allows local users to execute commands as root.
nvd