Hp Hp-Ux vulnerabilities
275 known vulnerabilities affecting hp/hp-ux.
Total CVEs
275
CISA KEV
1
actively exploited
Public exploits
53
Exploited in wild
8
Severity breakdown
CRITICAL42HIGH108MEDIUM97LOW28
Vulnerabilities
Page 9 of 14
CVE-2003-0333P4HIGHCVSS 7.2v10.20v11.002003-05-19
CVE-2003-0333 [HIGH] CVE-2003-0333: Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other ve
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
nvd
CVE-1999-0435P4HIGHCVSS 7.2v10.00v10.01+2 more1999-03-01
CVE-1999-0435 [HIGH] CVE-1999-0435: MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
nvd
CVE-2000-0005P4HIGHCVSS 7.2v7.00v7.02+33 more1999-01-02
CVE-2000-0005 [HIGH] CVE-2000-0005: HP-UX aserver program allows local users to gain privileges via a symlink attack.
HP-UX aserver program allows local users to gain privileges via a symlink attack.
nvd
CVE-2001-1198P4HIGHCVSS 7.2v10.01v10.10+3 more2001-12-15
CVE-2001-1198 [HIGH] CVE-2001-1198: RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privilege
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
nvd
CVE-1999-1088P4HIGHCVSS 7.2≤ 10.02v9+4 more1997-01-09
CVE-1999-1088 [HIGH] CVE-1999-1088: Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
nvd
CVE-2005-3564P4HIGHCVSS 7.2v11.00v11.112005-11-16
CVE-2005-3564 [HIGH] CVE-2005-3564: envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown att
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.
nvd
CVE-2010-2712P4MEDIUMCVSS 6.8vb.11.11vb.11.23+1 more2010-08-30
CVE-2010-2712 [MEDIUM] CVE-2010-2712: Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 all
Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.
nvd
CVE-2009-0719P4MEDIUMCVSS 6.0vb.11.11vb.11.23+1 more2009-04-29
CVE-2009-0719 [MEDIUM] CVE-2009-0719: Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to
Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.
nvd
CVE-2003-1087P4MEDIUMCVSS 5.0v11.00v11.04+2 more2003-12-31
CVE-2003-1087 [MEDIUM] CVE-2003-1087: Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running H
Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.
nvd
CVE-2013-6209P4MEDIUMCVSS 4.3vb.11.11vb.11.232014-03-14
CVE-2013-6209 [MEDIUM] CVE-2013-6209: Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows r
Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-2002-1615P4HIGHCVSS 7.2v10.20v11.00+3 more2002-09-13
CVE-2002-1615 [HIGH] CVE-2002-1615: Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to exec
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.
nvd
CVE-2001-0085P4HIGHCVSS 7.2v10.01v10.10+2 more2001-02-12
CVE-2001-0085 [HIGH] CVE-2001-0085: Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to ca
Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.
nvd
CVE-1999-1089P4HIGHCVSS 7.2≤ 10.20v9+1 more1996-12-13
CVE-1999-1089 [HIGH] CVE-1999-1089: Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
nvd
CVE-1999-0131P4HIGHCVSS 7.2v10.01v10.10+1 more1996-09-11
CVE-1999-0131 [HIGH] CVE-1999-0131: Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root a
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
nvd
CVE-2002-1618P4HIGHCVSS 7.2v10.20v11.00+1 more2002-10-16
CVE-2002-1618 [HIGH] CVE-2002-1618: JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky b
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.
nvd
CVE-1999-0309P4HIGHCVSS 7.2v10.00v10.01+3 more1997-02-01
CVE-1999-0309 [HIGH] CVE-1999-0309: HP-UX vgdisplay program gives root access to local users.
HP-UX vgdisplay program gives root access to local users.
nvd
CVE-1999-1247P4HIGHCVSS 7.2v91999-02-24
CVE-1999-1247 [HIGH] CVE-1999-1247: Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privi
Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.
nvd
CVE-2002-2363P4HIGHCVSS 7.2v11.002002-12-31
CVE-2002-2363 [HIGH] CWE-264 CVE-2002-2363: VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
nvd
CVE-2006-5452P4MEDIUMCVSS 4.6v11.00v11.4+3 more2006-10-23
CVE-2006-5452 [MEDIUM] CVE-2006-5452: Buffer overflow in dtmail on HP Tru64 UNIX 4.0F through 5.1B and HP-UX B.11.00 through B.11.23 allow
Buffer overflow in dtmail on HP Tru64 UNIX 4.0F through 5.1B and HP-UX B.11.00 through B.11.23 allows local users to execute arbitrary code via a long -a (aka attachment) argument.
nvd
CVE-2011-2398P4MEDIUMCVSS 6.8vb.11.11vb.11.23+1 more2011-07-11
CVE-2011-2398 [MEDIUM] CVE-2011-2398: Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows loc
Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges or cause a denial of service via unknown vectors.
nvd