VendorsDigitalunixall versions
Vulnerabilities

Digital Unix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2001-0134
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
Published 2001-02-14 · Modified
10.0EPSS 0.040
CVE-1999-0073
Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.
Published 1999-09-29 · Modified
10.0EPSS 0.031
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-2001-0369
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.007
CVE-1999-1458
Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-0406
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-1999-0358
Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.
Published 2000-10-13 · Modified
7.2EPSS 0.004
CVE-1999-0713
The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.
Published 2000-01-04 · Modified
7.2EPSS 0.003
CVE-1999-1210
xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-2000-0845
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.
Published 2000-10-18 · Modified
6.4EPSS 0.013
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-2000-0314
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
Published 2001-05-07 · Modified
5.0EPSS 0.018
CVE-2000-0315
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
Published 2001-05-07 · Modified
5.0EPSS 0.018
CVE-1999-1044
Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.
Published 2002-03-09 · Modified
4.6EPSS 0.003
CVE-1999-1221
dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.
Published 2001-09-12 · Modified
2.1EPSS 0.006
CVE-1999-0714
Vulnerability in Compaq Tru64 UNIX edauth command.
Published 2000-01-04 · Modified
2.1EPSS 0.004