| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges. |
| Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges. |
| Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges. |
| HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. |
| ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. |
| The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization. |
| Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd). |
| Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service. |
| HP CDE program includes the current directory in root's PATH variable. |
| Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x. |
| Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges. |
| rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. |
| The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read. |
| Buffer overflow in mstm in HP-UX allows local users to gain root access. |
| vhe_u_mnt program in HP-UX allows local users to create root files through symlinks. |
| ppl program in HP-UX allows local users to create root files through symlinks. |
| HP Remote Watch allows a remote user to gain root access. |
| ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value. |
| Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges. |
| Denial of service of inetd on Linux through SYN and RST packets. |