VendorsHPhp-uxall versions
Vulnerabilities

HP -UX family of operating systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

480CVEs
CVE-2021-20373
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
Published 2007-04-11 · Modified
7.5EPSS 0.014
CVE-2023-30445
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30449
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30448
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30446
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30447
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2020-4559
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.
Published 2020-08-28 · Modified
7.5EPSS 0.013
CVE-2023-30442
IBM Db2 denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2023-33850
IBM GSKit-Crypto information disclosure
Published 2023-08-22 · Modified
7.5EPSS 0.012
CVE-2003-0951
Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.
Published 2003-11-18 · Modified
7.5EPSS 0.012
CVE-2023-26281
IBM HTTP Server denial of service
Published 2023-02-28 · Modified
7.5EPSS 0.011
CVE-2006-7034
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
Published 2007-02-23 · Modified
7.5EPSS 0.011
CVE-2023-38741
IBM TXSeries for Multiplatforms denial of service
Published 2023-08-14 · Modified
7.5EPSS 0.010
CVE-2023-28513
IBM MQ denial of service
Published 2023-07-19 · Modified
7.5EPSS 0.010
CVE-2021-29722
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2021-29723
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.
Published 2021-08-30 · Modified
7.5EPSS 0.009
CVE-2021-39002
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published 2021-12-09 · Modified
7.5EPSS 0.009
CVE-2020-4937
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.
Published 2020-11-20 · Modified
7.5EPSS 0.008
CVE-2022-43929
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2023-02-17 · Modified
7.5EPSS 0.007
CVE-2022-43927
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.006
CVE-2022-43917
IBM WebSphere Application Server information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.005
CVE-2023-50271
HP-UX System Management Homepage, Disclosure of Information
Published 2023-12-17 · Modified
7.5EPSS 0.005
CVE-2023-1995
Insufficient Logging Vulnerability in HiRDB
Published 2023-08-29 · Modified
7.5EPSS 0.005
CVE-2025-33142
IBM WebSphere Application Server information disclosure
Published 2025-08-14 · Analyzed
7.5EPSS 0.003
CVE-2024-38320
IBM Storage Protect for Virtual Environments: Data Protection for VMware information disclosure
Published 2025-01-27 · Analyzed
7.5EPSS 0.002
CVE-2026-13476
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
Published 2026-08-12 · Analyzed
7.3EPSS 0.004
CVE-2016-5995
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Published 2016-10-01 · Modified
7.3EPSS 0.004
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Published 2003-04-02 · Modified
7.2EPSS 0.094
CVE-2003-1097
Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.
Published 2005-03-11 · Modified
7.21 PoCEPSS 0.040
CVE-2002-1614
Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.
Published 2005-03-25 · Modified
7.21 PoCEPSS 0.021
CVE-2003-1375
Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.
Published 2007-10-19 · Modified
7.21 PoCEPSS 0.017
CVE-2001-0979
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.
Published 2002-02-02 · Modified
7.22 PoCEPSS 0.016
CVE-2003-1461
Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).
Published 2007-10-23 · Modified
7.21 PoCEPSS 0.015
CVE-2000-1028
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.
Published 2000-11-29 · Modified
7.22 PoCEPSS 0.015
CVE-2000-1134
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
Published 2000-12-19 · Modified
7.22 PoCEPSS 0.014
CVE-2003-0089
Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.
Published 2003-11-18 · Modified
7.21 PoCEPSS 0.014
CVE-2003-1098
The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.
Published 2005-03-11 · Modified
7.2EPSS 0.013
CVE-1999-0050
Buffer overflow in HP-UX newgrp program.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.012
CVE-2003-1359
Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.
Published 2007-10-17 · Modified
7.22 PoCEPSS 0.012
← Prev4 / 12Next →