VendorsHPhp-ux10.20
Vulnerabilities

HP -UX family of operating systems 10.20

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2002-1615
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.
Published 2005-03-25 · Modified
7.2EPSS 0.008
CVE-2003-0333
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
Published 2003-05-23 · Modified
7.2EPSS 0.007
CVE-2001-0085
Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.
Published 2001-05-07 · Modified
7.2EPSS 0.006
CVE-1999-0435
MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-0324
ppl program in HP-UX allows local users to create root files through symlinks.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-2003-1360
Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.
Published 2007-10-17 · Modified
7.2EPSS 0.006
CVE-2002-1612
Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2002-1613
Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2003-0061
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
Published 2005-04-15 · Modified
7.2EPSS 0.006
CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2000-0801
Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.
Published 2000-09-21 · Modified
7.2EPSS 0.006
CVE-2001-1182
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.
Published 2002-03-15 · Modified
7.2EPSS 0.005
CVE-2000-0005
HP-UX aserver program allows local users to gain privileges via a symlink attack.
Published 2000-02-04 · Modified
7.2EPSS 0.005
CVE-1999-0309
HP-UX vgdisplay program gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.005
CVE-2001-1198
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
Published 2002-03-15 · Modified
7.2EPSS 0.005
CVE-1999-1088
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-1144
Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2003-1356
The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.
Published 2007-10-14 · Modified
7.2EPSS 0.005
CVE-1999-0016
Land IP denial of service.
Published 1999-09-29 · Modified
5.05 PoCEPSS 0.957
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-1999-0015
Teardrop IP denial of service.
Published 2000-02-04 · Modified
5.01 PoCEPSS 0.354
CVE-2002-2262
Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.
Published 2007-10-18 · Modified
5.0EPSS 0.023
CVE-1999-0779
Denial of service in HP-UX SharedX recserv program.
Published 2000-01-04 · Modified
5.0EPSS 0.018
CVE-2002-1473
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.
Published 2003-03-18 · Modified
4.62 PoCEPSS 0.044
CVE-2002-1606
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain privileges via (1) lpc, (2) lpd, (3) lpq, (4) lpr, or (5) lprm.
Published 2005-03-25 · Modified
4.6EPSS 0.015
CVE-2000-0468
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
Published 2000-10-13 · Modified
4.61 PoCEPSS 0.008
CVE-2002-1607
Buffer overflow in ypmatch in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.
Published 2005-03-25 · Modified
4.6EPSS 0.007
CVE-2002-1608
Buffer overflow in traceroute in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.
Published 2005-03-25 · Modified
4.6EPSS 0.007
CVE-2000-1031
Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.
Published 2001-01-22 · Modified
4.6EPSS 0.007
CVE-2002-1611
Buffer overflow in quot in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
4.6EPSS 0.006
CVE-2002-1609
Buffer overflow in binmail in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
4.6EPSS 0.006
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-1999-0326
Vulnerability in HP-UX mediainit program.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-1311
Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2000-0414
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
Published 2000-07-12 · Modified
4.6EPSS 0.005
CVE-1999-0436
Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
Published 1999-09-29 · Modified
4.6EPSS 0.005
CVE-1999-1249
movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.
Published 2002-03-09 · Modified
4.6EPSS 0.005
CVE-1999-1308
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
Published 2001-09-12 · Modified
4.6EPSS 0.005
CVE-2000-1127
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.
Published 2000-12-19 · Modified
3.61 PoCEPSS 0.010
← Prev2 / 3Next →