cbcvebase.

Hp Hp-Ux vulnerabilities

275 known vulnerabilities affecting hp/hp-ux.

Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28

Vulnerabilities

Page 6 of 14
CVE-2002-0678P4HIGHCVSS 7.2v10.10v10.20+3 more2002-07-23
CVE-2002-0678 [HIGH] CVE-2002-0678: CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a syml CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
nvd
CVE-1999-0353P4CRITICALCVSS 9.3v10.01v10.10+2 more1999-02-10
CVE-1999-0353 [CRITICAL] CVE-1999-0353: rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool dire rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
nvd
CVE-1999-1408P4LOWCVSS 2.1PoCv9.05v10.01+1 more1997-03-05
CVE-1999-1408 [LOW] CVE-1999-1408: Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
nvd
CVE-2015-2126P4HIGHCVSS 7.2v11.11iv2v11.11iv32015-07-06
CVE-2015-2126 [HIGH] CWE-264 CVE-2015-2126: Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privilege Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.
nvd
CVE-2012-0126P4MEDIUMCVSS 5.8v11.11v11.232012-03-28
CVE-2012-0126 [MEDIUM] CVE-2012-0126: Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attac Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.
nvd
CVE-2004-0809P4MEDIUMCVSS 5.0v11.00v11.11+2 more2004-09-16
CVE-2004-0809 [MEDIUM] CVE-2004-0809: The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
nvd
CVE-2000-0159P4HIGHCVSS 7.5v11.002000-02-17
CVE-2000-0159 [HIGH] CVE-2000-0159: HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set t HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.
nvd
CVE-2003-0951P4HIGHCVSS 7.5v11.232003-12-15
CVE-2003-0951 [HIGH] CVE-2003-0951: Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provide Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.
nvd
CVE-2010-4108P4MEDIUMCVSS 6.8vb.11.11vb.11.23+1 more2010-12-08
CVE-2010-4108 [MEDIUM] CVE-2010-4108: HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows re HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows remote authenticated users to cause a denial of service via unspecified vectors.
nvd
CVE-2008-0713P4MEDIUMCVSS 6.8v11.11v11.23+1 more2008-05-13
CVE-2008-0713 [MEDIUM] CVE-2008-0713: Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote au Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.
nvd
CVE-2009-2682P4HIGHCVSS 7.2vb.11.23vb.11.312009-09-24
CVE-2009-2682 [HIGH] CWE-264 CVE-2009-2682: Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
nvd
CVE-2011-0896P4MEDIUMCVSS 6.8vb.11.312011-04-15
CVE-2011-0896 [MEDIUM] CVE-2011-0896: Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote au Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors.
nvd
CVE-2003-1098P4HIGHCVSS 7.2v11.222003-12-31
CVE-2003-1098 [HIGH] CVE-2003-1098: The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows loc The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v8.05v11.00+2 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2007-4125P4HIGHCVSS 7.1v11.11v11.23+1 more2007-08-01
CVE-2007-4125 [HIGH] CVE-2007-4125: Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality i Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.
nvd
CVE-2006-5091P4HIGHCVSS 7.2v11.11v11.232006-09-29
CVE-2006-5091 [HIGH] CVE-2006-5091: Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gai Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gain privileges or obtain "unauthorized access" via unspecified vectors.
nvd
CVE-2006-3335P4HIGHCVSS 7.2v11.00v11.4+2 more2006-07-03
CVE-2006-3335 [HIGH] CVE-2006-3335: Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local user Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2006-4188P4MEDIUMCVSS 5.0v11.00v11.4+2 more2006-08-17
CVE-2006-4188 [MEDIUM] CVE-2006-4188: Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-1999-0707P4HIGHCVSS 7.5v10.201999-07-01
CVE-1999-0707 [HIGH] CVE-1999-0707: The default FTP configuration in HP Visualize Conference allows conference users to send a file to o The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.
nvd
CVE-1999-0022P4HIGHCVSS 7.8v10.001996-07-03
CVE-1999-0022 [HIGH] CWE-125 CVE-1999-0022: Local user gains root privileges via buffer overflow in rdist, via expstr() function. Local user gains root privileges via buffer overflow in rdist, via expstr() function.
nvd
Hp Hp-Ux vulnerabilities | cvebase