Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28
Vulnerabilities
Page 5 of 14
CVE-2005-3670P3HIGHCVSS 7.8v11.00v11.11+1 more2005-11-18
CVE-2005-3670 [HIGH] CVE-2005-3670: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suit
nvd
CVE-2005-3565P3HIGHCVSS 7.5v11.00v11.11+1 more2005-11-16
CVE-2005-3565 [HIGH] CVE-2005-3565: Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trus
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.
nvd
CVE-2005-4451P3HIGHCVSS 7.5v11.112005-12-21
CVE-2005-4451 [HIGH] CVE-2005-4451: Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain a
Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.
nvd
CVE-2002-0677P3HIGHCVSS 7.5v10.10v10.20+3 more2002-07-23
CVE-2002-0677 [HIGH] CVE-2002-0677: CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory loca
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
nvd
CVE-2009-2679P3HIGHCVSS 7.8vb.11.11vb.11.23+1 more2009-10-05
CVE-2009-2679 [HIGH] CVE-2009-2679: Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attacker
Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.
nvd
CVE-1999-0097P4CRITICALCVSS 10.0v9.00v9.01+14 more1997-10-29
CVE-1999-0097 [CRITICAL] CVE-1999-0097: The AIX FTP client can be forced to execute commands from a malicious server through shell metachara
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
nvd
CVE-2000-0972P4MEDIUMCVSS 5.5PoCv11.002000-12-19
CVE-2000-0972 [MEDIUM] CWE-59 CVE-2000-0972: HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symli
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
nvd
CVE-2001-1264P4CRITICALCVSS 10.0v11.042001-07-19
CVE-2001-1264 [CRITICAL] CVE-2001-1264: Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allo
Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.
nvd
CVE-2008-4418P4HIGHCVSS 7.8vb.11.11vb.11.23+1 more2008-12-11
CVE-2008-4418 [HIGH] CVE-2008-4418: Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers t
Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v8.05v11.00+2 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-1999-0057P4HIGHCVSS 7.5v9v10.00+2 more1998-11-16
CVE-1999-0057 [HIGH] CVE-1999-0057: Vacation program allows command execution by remote users through a sendmail command.
Vacation program allows command execution by remote users through a sendmail command.
nvd
CVE-2000-1127P4LOWCVSS 3.6PoCv10.202001-01-09
CVE-2000-1127 [LOW] CVE-2000-1127: registrar in the HP resource monitor service allows local users to read and modify arbitrary files b
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.
nvd
CVE-2008-1664P4HIGHCVSS 7.8v11.23v11.312008-08-08
CVE-2008-1664 [HIGH] CVE-2008-1664: Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a
Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-2007-6419P4HIGHCVSS 7.8v11.11v11.23+1 more2007-12-24
CVE-2007-6419 [HIGH] CVE-2007-6419: Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote a
Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2000-0468P4MEDIUMCVSS 4.6PoCv10.20v11.002000-06-02
CVE-2000-0468 [MEDIUM] CVE-2000-0468: man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
nvd
CVE-2003-0064P4HIGHCVSS 7.5v10.20v10.24+8 more2003-03-03
CVE-2003-0064 [HIGH] CVE-2003-0064: The dtterm terminal emulator allows attackers to modify the window title via a certain character esc
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
nvd
CVE-2004-0952P4MEDIUMCVSS 6.4v11.00v11.11+2 more2004-12-31
CVE-2004-0952 [MEDIUM] CVE-2004-0952: HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes t
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.
nvd
CVE-2014-7874P4MEDIUMCVSS 6.8vb.11.23vb.11.312014-10-19
CVE-2014-7874 [MEDIUM] CWE-352 CVE-2014-7874: Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2006-1389P4HIGHCVSS 7.8v11.00v11.4+1 more2006-03-25
CVE-2006-1389 [HIGH] CVE-2006-1389: Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers
Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-1999-0008P4CRITICALCVSS 10.0v10.34v11.001998-06-08
CVE-1999-0008 [CRITICAL] CVE-1999-0008: Buffer overflow in NIS+, in Sun's rpc.nisd program.
Buffer overflow in NIS+, in Sun's rpc.nisd program.
nvd