Vulnerabilities > HP > HP UX > 11.00

DATE CVE VULNERABILITY TITLE RISK
2005-05-31 CVE-2005-1771 Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.
network
low complexity
hp
7.5
2005-05-02 CVE-2005-1192 Remote Denial Of Service vulnerability in HP-UX ICMP PMTUD
Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.
network
low complexity
hp
5.0
2005-03-01 CVE-2004-1029 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
network
hp sun symantec conectiva gentoo CWE-264
critical
9.3
2005-02-24 CVE-2005-0547 Restricted File Access vulnerability in HP-UX FTP Server
Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."
local
low complexity
hp
4.6
2005-02-10 CVE-2005-0364 Denial-Of-Service vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.
network
low complexity
hp
5.0
2005-02-09 CVE-2004-0965 Local Privilege Escalation vulnerability in HP-UX STMKFONT
stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.
local
low complexity
hp
7.2
2005-02-09 CVE-2004-0940 Incorrect Calculation of Buffer Size vulnerability in multiple products
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
local
low complexity
openpkg apache slackware hp suse trustix CWE-131
7.8
2004-12-31 CVE-2004-2753 Local Insecure File Access vulnerability in HP SharedX
Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of "files in a potentially insecure manner."
local
low complexity
hp
5.6
2004-12-31 CVE-2004-2693 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 11.00/11.04/11.11
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.
local
low complexity
hp CWE-264
7.2
2004-12-31 CVE-2004-2665 Denial-Of-Service vulnerability in HP Hp-Ux 11.00/11.11/11.4
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.
local
low complexity
hp
4.9