VendorsHPhp-uxall versions
Vulnerabilities

HP -UX family of operating systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

480CVEs
CVE-1999-0311
fpkg2swpk in HP-UX allows local users to gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.005
CVE-2000-0078
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.
Published 2000-02-04 · Modified
7.2EPSS 0.005
CVE-1999-0309
HP-UX vgdisplay program gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.005
CVE-2001-1198
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
Published 2002-03-15 · Modified
7.2EPSS 0.005
CVE-2008-1659
Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors.
Published 2008-05-08 · Modified
7.2EPSS 0.005
CVE-1999-1145
Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-1146
Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-1247
Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-1134
Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-1135
Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-1999-1088
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.005
CVE-2001-0266
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
Published 2001-05-07 · Modified
7.2EPSS 0.005
CVE-1999-1144
Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2006-2574
Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.
Published 2006-05-24 · Modified
7.2EPSS 0.005
CVE-2006-5091
Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gain privileges or obtain "unauthorized access" via unspecified vectors.
Published 2006-09-29 · Modified
7.2EPSS 0.005
CVE-2004-1328
Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.
Published 2005-01-06 · Modified
7.2EPSS 0.005
CVE-2005-3779
Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.
Published 2005-11-23 · Modified
7.2EPSS 0.005
CVE-1999-1139
Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2007-5946
Unspecified vulnerability in the Aries PA-RISC emulator on HP-UX B.11.23 and B.11.31 on the IA-64 platform allows local users to obtain unspecified access.
Published 2007-11-14 · Modified
7.2EPSS 0.005
CVE-2008-0707
HP StorageWorks Library and Tape Tools (LTT) before 4.5 SR1 on HP-UX B.11.11 and B.11.23 allows local users to gain privileges via unspecified vectors.
Published 2008-03-20 · Modified
7.2EPSS 0.005
CVE-2005-3564
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.
Published 2005-11-16 · Modified
7.2EPSS 0.005
CVE-2003-1356
The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.
Published 2007-10-14 · Modified
7.2EPSS 0.005
CVE-2002-2363
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
Published 2007-10-29 · Modified
7.2EPSS 0.005
CVE-2006-1689
Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.
Published 2006-04-10 · Modified
7.2EPSS 0.005
CVE-2004-2693
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.
Published 2007-10-06 · Modified
7.2EPSS 0.005
CVE-2006-0436
Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.
Published 2006-01-26 · Modified
7.2EPSS 0.005
CVE-2006-3335
Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.
Published 2006-07-03 · Modified
7.2EPSS 0.004
CVE-2008-3357
Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."
Published 2008-08-05 · Modified
7.2EPSS 0.004
CVE-2007-1086
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
Published 2007-02-23 · Modified
7.2EPSS 0.004
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Published 2012-03-20 · Modified
7.2EPSS 0.003
CVE-2012-2291
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
Published 2013-01-21 · Modified
7.2EPSS 0.003
CVE-2013-4002
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Published 2013-07-23 · Modified
7.1EPSS 0.247
CVE-2007-4125
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.
Published 2007-08-01 · Modified
7.1EPSS 0.024
CVE-2007-0396
Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.
Published 2007-01-19 · Modified
7.1EPSS 0.023
CVE-2019-11989
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.
Published 2019-07-19 · Modified
7.1EPSS 0.017
CVE-2011-0343
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
Published 2011-01-28 · Modified
6.9EPSS 0.004
CVE-2011-3337
eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows local users to gain privileges via a Trojan horse gauntlet program in an arbitrary directory under /usr/local/.
Published 2012-01-04 · Modified
6.9EPSS 0.003
CVE-2013-5904
Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Published 2014-01-15 · Modified
6.8EPSS 0.049
CVE-2013-5870
Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.
Published 2014-01-15 · Modified
6.8EPSS 0.048
CVE-2007-2191
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
Published 2007-04-24 · Modified
6.81 PoCEPSS 0.045
← Prev6 / 12Next →