VendorsHPhp-uxall versions
Vulnerabilities

HP -UX family of operating systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

480CVEs
CVE-2025-27907
IBM WebSphere Application Server server-side request forgery
Published 2025-04-22 · Analyzed
4.1EPSS 0.003
CVE-1999-0524
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
Published 2000-02-04 · Modified
4.0EPSS 0.322
CVE-2010-0451
The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests.
Published 2010-03-29 · Modified
4.0EPSS 0.032
CVE-2013-6219
Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
Published 2014-04-19 · Modified
3.8EPSS 0.003
CVE-2023-33847
IBM CICS TX information disclosure
Published 2023-06-08 · Modified
3.7EPSS 0.006
CVE-2023-33849
IBM CICS TX information disclosure
Published 2023-06-07 · Modified
3.7EPSS 0.004
CVE-2000-1127
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.
Published 2000-12-19 · Modified
3.61 PoCEPSS 0.010
CVE-2002-2270
Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.
Published 2007-10-18 · Modified
3.6EPSS 0.004
CVE-2012-0125
Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.
Published 2012-03-28 · Modified
3.3EPSS 0.004
CVE-2007-4590
The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.
Published 2007-08-29 · Modified
3.3EPSS 0.004
CVE-2013-6335
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.
Published 2014-08-26 · Modified
3.3EPSS 0.003
CVE-2020-4629
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
Published 2020-09-30 · Modified
3.3EPSS 0.003
CVE-2011-4160
Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors.
Published 2011-11-24 · Modified
3.2EPSS 0.003
CVE-1999-1408
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
Published 2001-09-12 · Modified
2.11 PoCEPSS 0.010
CVE-2003-1099
shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.
Published 2005-03-11 · Modified
2.1EPSS 0.009
CVE-2002-1409
ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."
Published 2003-03-18 · Modified
2.1EPSS 0.006
CVE-2002-0577
Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.
Published 2002-06-11 · Modified
2.1EPSS 0.006
CVE-2002-0992
Unknown vulnerability in IPV6 functionality for DCE daemons (1) dced or (2) rpcd on HP-UX 11.11 allows attackers to cause a denial of service (crash) via an attack that modifies internal data.
Published 2002-08-31 · Modified
2.1EPSS 0.006
CVE-2001-1439
Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.
Published 2005-04-21 · Modified
2.1EPSS 0.006
CVE-2002-0798
Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.
Published 2002-07-26 · Modified
2.1EPSS 0.005
CVE-2002-1610
Unknown vulnerability in ping in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to cause a denial of service.
Published 2005-03-25 · Modified
2.1EPSS 0.005
CVE-2001-1136
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.
Published 2002-03-15 · Modified
2.1EPSS 0.005
CVE-2001-0219
Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.
Published 2001-05-07 · Modified
2.1EPSS 0.005
CVE-2002-1668
HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.
Published 2005-06-21 · Modified
2.1EPSS 0.005
CVE-2006-2551
Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local users to cause an unspecified denial of service via unknown vectors.
Published 2006-05-23 · Modified
2.1EPSS 0.005
CVE-2001-1564
setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available disk space.
Published 2005-07-14 · Modified
2.1EPSS 0.005
CVE-2006-4820
Unspecified vulnerability in X.25 on HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
Published 2006-09-15 · Modified
2.1EPSS 0.005
CVE-2001-0488
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
Published 2001-09-18 · Modified
2.1EPSS 0.005
CVE-1999-0132
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
2.1EPSS 0.005
CVE-1999-1205
nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.
Published 2002-03-09 · Modified
2.1EPSS 0.005
CVE-2005-3295
Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."
Published 2005-10-23 · Modified
2.1EPSS 0.005
CVE-2006-4187
Unspecified vulnerability in HP-UX B.11.00, B.11.11 and B.11.23, when running in trusted mode, allows local users to cause a denial of service via unspecified vectors.
Published 2006-08-17 · Modified
2.1EPSS 0.004
CVE-2001-0809
Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.
Published 2001-11-22 · Modified
2.1EPSS 0.004
CVE-2001-0105
Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.
Published 2001-05-07 · Modified
2.1EPSS 0.004
CVE-1999-1251
Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.
Published 2001-09-12 · Modified
2.1EPSS 0.004
CVE-2003-1437
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Published 2007-10-23 · Modified
2.1EPSS 0.002
CVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Published 2000-02-04 · Modified
1.9EPSS 0.009
CVE-2005-2993
Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).
Published 2005-09-20 · Modified
1.7EPSS 0.007
CVE-2007-4179
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.
Published 2007-08-08 · Modified
1.5EPSS 0.003
CVE-2001-1256
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.
Published 2002-05-03 · Modified
1.2EPSS 0.061
← Prev12 / 12