VendorsHPhp-uxany version
Vulnerabilities

HP -UX family of operating systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2021-20373
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
Published 2007-04-11 · Modified
7.5EPSS 0.014
CVE-2023-30445
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30449
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30448
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30446
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30447
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2020-4559
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.
Published 2020-08-28 · Modified
7.5EPSS 0.013
CVE-2023-30442
IBM Db2 denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2023-33850
IBM GSKit-Crypto information disclosure
Published 2023-08-22 · Modified
7.5EPSS 0.012
CVE-2023-26281
IBM HTTP Server denial of service
Published 2023-02-28 · Modified
7.5EPSS 0.011
CVE-2006-7034
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
Published 2007-02-23 · Modified
7.5EPSS 0.011
CVE-2023-38741
IBM TXSeries for Multiplatforms denial of service
Published 2023-08-14 · Modified
7.5EPSS 0.010
CVE-2023-28513
IBM MQ denial of service
Published 2023-07-19 · Modified
7.5EPSS 0.010
CVE-2021-29723
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2021-29722
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2021-39002
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published 2021-12-09 · Modified
7.5EPSS 0.009
CVE-2020-4937
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.
Published 2020-11-20 · Modified
7.5EPSS 0.008
CVE-2022-43929
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2023-02-17 · Modified
7.5EPSS 0.007
CVE-2022-43927
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.006
CVE-2022-43917
IBM WebSphere Application Server information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.005
CVE-2023-50271
HP-UX System Management Homepage, Disclosure of Information
Published 2023-12-17 · Modified
7.5EPSS 0.005
CVE-2023-1995
Insufficient Logging Vulnerability in HiRDB
Published 2023-08-29 · Modified
7.5EPSS 0.005
CVE-2025-33142
IBM WebSphere Application Server information disclosure
Published 2025-08-14 · Analyzed
7.5EPSS 0.003
CVE-2024-38320
IBM Storage Protect for Virtual Environments: Data Protection for VMware information disclosure
Published 2025-01-27 · Analyzed
7.5EPSS 0.002
CVE-2026-13476
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
Published 2026-08-12 · Analyzed
7.3EPSS 0.004
CVE-2016-5995
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Published 2016-10-01 · Modified
7.3EPSS 0.004
CVE-1999-1089
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
Published 2001-09-12 · Modified
7.2EPSS 0.006
CVE-1999-0127
swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-1161
Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-1145
Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-1146
Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2001-0266
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
Published 2001-05-07 · Modified
7.2EPSS 0.005
CVE-1999-1088
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-1139
Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2008-3357
Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."
Published 2008-08-05 · Modified
7.2EPSS 0.004
CVE-2007-1086
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
Published 2007-02-23 · Modified
7.2EPSS 0.004
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Published 2012-03-20 · Modified
7.2EPSS 0.003
CVE-2012-2291
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
Published 2013-01-21 · Modified
7.2EPSS 0.003
CVE-2013-4002
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Published 2013-07-23 · Modified
7.1EPSS 0.247
← Prev2 / 5Next →