VendorsHPhp-uxall versions
Vulnerabilities

HP -UX family of operating systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

480CVEs
CVE-2001-0379
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.
Published 2001-09-18 · Modified
4.6EPSS 0.005
CVE-1999-1136
Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.
Published 2002-03-09 · Modified
4.6EPSS 0.005
CVE-1999-0308
HP-UX gwind program allows users to modify arbitrary files.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-0326
Vulnerability in HP-UX mediainit program.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-1311
Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2000-0083
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
Published 2000-04-18 · Modified
4.6EPSS 0.005
CVE-1999-1239
HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2000-0730
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.
Published 2000-10-13 · Modified
4.6EPSS 0.005
CVE-2000-0414
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
Published 2000-07-12 · Modified
4.6EPSS 0.005
CVE-2004-1375
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.
Published 2005-01-19 · Modified
4.6EPSS 0.005
CVE-2001-1509
geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.
Published 2005-07-14 · Modified
4.6EPSS 0.005
CVE-1999-0436
Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-1249
movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.
Published 2002-03-09 · Modified
4.6EPSS 0.005
CVE-1999-1308
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-1999-0432
ftp on HP-UX 11.00 allows local users to gain privileges.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-0423
Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-2006-1248
Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.
Published 2006-03-17 · Modified
4.6EPSS 0.005
CVE-1999-1238
Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2001-0607
asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.
Published 2001-07-27 · Modified
4.6EPSS 0.005
CVE-1999-1133
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-1999-1242
Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2015-3316
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, allows local users to gain privileges via an unspecified environment variable.
Published 2015-06-17 · Modified
4.6EPSS 0.005
CVE-2008-3389
Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.
Published 2008-08-05 · Modified
4.6EPSS 0.004
CVE-1999-1248
Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.004
CVE-2015-3317
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly perform bounds checking, which allows local users to gain privileges via unspecified vectors.
Published 2015-06-17 · Modified
4.6EPSS 0.004
CVE-2015-3318
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly validate an unspecified variable, which allows local users to gain privileges via unknown vectors.
Published 2015-06-17 · Modified
4.6EPSS 0.004
CVE-2006-4795
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.
Published 2006-09-14 · Modified
4.6EPSS 0.003
CVE-2008-4416
Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.
Published 2008-12-05 · Modified
4.6EPSS 0.003
CVE-2010-1030
Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.
Published 2010-03-31 · Modified
4.4EPSS 0.003
CVE-2011-0891
Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.
Published 2011-04-03 · Modified
4.4EPSS 0.003
CVE-2015-4000
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
Published 2015-05-21 · Modified
4.3EPSS 0.999
CVE-2014-0382
Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.
Published 2014-01-15 · Modified
4.3EPSS 0.049
CVE-2003-0914
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
Published 2003-12-02 · Modified
4.3EPSS 0.032
CVE-2007-5302
Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2007-10-09 · Modified
4.3EPSS 0.029
CVE-2013-6209
Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.
Published 2014-03-14 · Modified
4.3EPSS 0.027
CVE-2010-0452
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2010-03-29 · Modified
4.3EPSS 0.027
CVE-2007-6232
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
Published 2007-12-04 · Modified
4.32 PoCEPSS 0.016
CVE-2009-4777
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
Published 2010-04-21 · Modified
4.3EPSS 0.014
CVE-2019-4377
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.
Published 2019-06-25 · Modified
4.3EPSS 0.013
CVE-2020-4299
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.
Published 2020-05-14 · Modified
4.3EPSS 0.010
← Prev11 / 12Next →