cbcvebase.

Hp Hp-Ux vulnerabilities

275 known vulnerabilities affecting hp/hp-ux.

Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28

Vulnerabilities

Page 4 of 14
CVE-2009-0418P3CRITICALCVSS 9.3vb.11.11vb.11.23+1 more2009-02-04
CVE-2009-0418 [CRITICAL] CVE-2009-0418: The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward In
nvd
CVE-2006-5557P4MEDIUMCVSS 4.6PoCv11.00v11.4+1 more2006-10-27
CVE-2006-5557 [MEDIUM] CVE-2006-5557: Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and poss Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
nvd
CVE-2006-5556P4MEDIUMCVSS 4.6PoCv11.00v11.4+1 more2006-10-27
CVE-2006-5556 [MEDIUM] CVE-2006-5556: Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 a Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.
nvd
CVE-2000-1028P4HIGHCVSS 7.2PoCv9.00v9.01+9 more2000-12-11
CVE-2000-1028 [HIGH] CVE-2000-1028: Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l c Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.
nvd
CVE-2003-0196P3CRITICALCVSS 10.0v10.01v10.20+6 more2003-05-05
CVE-2003-0196 [CRITICAL] CVE-2003-0196: Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary cod Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
nvd
CVE-2004-1332P3HIGHCVSS 7.5v10.01v10.10+8 more2004-12-31
CVE-2004-1332 [HIGH] CVE-2004-1332: Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, a Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.
nvd
CVE-2000-0702P4HIGHCVSS 7.2PoCv11.002000-10-20
CVE-2000-0702 [HIGH] CVE-2000-0702: The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.
nvd
CVE-2001-0249P3CRITICALCVSS 9.8v11.002001-06-18
CVE-2001-0249 [CRITICAL] CWE-131 CVE-2001-0249: Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by cr Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
nvd
CVE-1999-0014P4HIGHCVSS 7.2PoCv10.10v10.20+1 more1998-01-21
CVE-1999-0014 [HIGH] CVE-1999-0014: Unauthorized privileged access or denial of service via dtappgather program in CDE. Unauthorized privileged access or denial of service via dtappgather program in CDE.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v10.20v10.24+5 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-2002-1794P3CRITICALCVSS 10.0v11.00v11.112002-12-31
CVE-2002-1794 [CRITICAL] CVE-2002-1794: Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allow Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.
nvd
CVE-2000-1134P4HIGHCVSS 7.2PoCv11.112001-01-09
CVE-2000-1134 [HIGH] CVE-2000-1134: Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
nvd
CVE-2005-4090P3CRITICALCVSS 10.0v11.00v11.11+2 more2005-12-08
CVE-2005-4090 [CRITICAL] CVE-2005-4090: Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attacker Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.
nvd
CVE-2001-0248P3CRITICALCVSS 9.8v11.002001-06-18
CVE-2001-0248 [CRITICAL] CWE-131 CVE-2001-0248: Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by cr Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
nvd
CVE-2001-0668P3HIGHCVSS 7.5v10.01v10.10+3 more2001-09-20
CVE-2001-0668 [HIGH] CVE-2001-0668: Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attack Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.
nvd
CVE-1999-1573P3CRITICALCVSS 10.0v10.00v10.01+4 more1999-12-28
CVE-1999-1573 [CRITICAL] CVE-1999-1573: Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, ( Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.
nvd
CVE-1999-1160P3CRITICALCVSS 10.0v9v101997-02-02
CVE-1999-1160 [CRITICAL] CVE-1999-1160: Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain roo Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.
nvd
CVE-2002-1604P3HIGHCVSS 7.5v10.20v11.00+3 more2002-09-02
CVE-2002-1604 [HIGH] CVE-2002-1604: Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbi Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
nvd
CVE-2000-1126P4CRITICALCVSS 10.0v10.01v10.10+4 more2001-01-09
CVE-2000-1126 [CRITICAL] CVE-2000-1126: Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to exec Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.
nvd
CVE-2007-6425P3CRITICALCVSS 10.0v11.312008-01-23
CVE-2007-6425 [CRITICAL] CWE-119 CVE-2007-6425: Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.
nvd
Hp Hp-Ux vulnerabilities | cvebase