VendorsHPhp-uxall versions
Vulnerabilities

HP -UX family of operating systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

480CVEs
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-1999-0014
Unauthorized privileged access or denial of service via dtappgather program in CDE.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.012
CVE-2000-0702
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.
Published 2001-01-22 · Modified
7.21 PoCEPSS 0.012
CVE-1999-0130
Local users can start Sendmail in daemon mode and gain root privileges.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0693
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.010
CVE-2000-0077
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.010
CVE-2003-0840
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.
Published 2003-10-09 · Modified
7.21 PoCEPSS 0.010
CVE-2003-1358
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
Published 2007-10-17 · Modified
7.21 PoCEPSS 0.010
CVE-2001-0551
Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.
Published 2002-02-18 · Modified
7.2EPSS 0.009
CVE-2002-1615
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.
Published 2005-03-25 · Modified
7.2EPSS 0.008
CVE-2001-1181
Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.
Published 2002-03-15 · Modified
7.2EPSS 0.007
CVE-1999-0138
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
Published 1999-09-29 · Modified
7.2EPSS 0.007
CVE-2004-0965
stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.
Published 2004-10-26 · Modified
7.2EPSS 0.007
CVE-2003-0333
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
Published 2003-05-23 · Modified
7.2EPSS 0.007
CVE-2007-2351
Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.
Published 2007-04-30 · Modified
7.2EPSS 0.006
CVE-2004-1764
Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.
Published 2005-03-10 · Modified
7.2EPSS 0.006
CVE-2001-0085
Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.
Published 2001-05-07 · Modified
7.2EPSS 0.006
CVE-1999-0435
MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-0324
ppl program in HP-UX allows local users to create root files through symlinks.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-1999-0336
Buffer overflow in mstm in HP-UX allows local users to gain root access.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-0307
Buffer overflow in HP-UX cstm program allows local users to gain root privileges.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-1089
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
Published 2001-09-12 · Modified
7.2EPSS 0.006
CVE-2003-1360
Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.
Published 2007-10-17 · Modified
7.2EPSS 0.006
CVE-2002-1612
Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2002-1613
Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2002-1406
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
Published 2003-03-18 · Modified
7.2EPSS 0.006
CVE-2003-0061
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
Published 2005-04-15 · Modified
7.2EPSS 0.006
CVE-1999-0127
swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.
Published 2005-03-25 · Modified
7.2EPSS 0.006
CVE-2000-0801
Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.
Published 2000-09-21 · Modified
7.2EPSS 0.006
CVE-2015-2126
Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.
Published 2015-07-06 · Modified
7.2EPSS 0.006
CVE-1999-0962
Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.
Published 2000-01-04 · Modified
7.2EPSS 0.005
CVE-2001-1182
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.
Published 2002-03-15 · Modified
7.2EPSS 0.005
CVE-2000-0005
HP-UX aserver program allows local users to gain privileges via a symlink attack.
Published 2000-02-04 · Modified
7.2EPSS 0.005
CVE-1999-0690
HP CDE program includes the current directory in root's PATH variable.
Published 2000-01-04 · Modified
7.2EPSS 0.005
CVE-2009-2682
Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
Published 2009-09-24 · Modified
7.2EPSS 0.005
CVE-1999-1161
Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-0309
HP-UX vgdisplay program gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.005
← Prev5 / 12Next →