Vulnerabilities > HP > HP UX > 11.11

DATE CVE VULNERABILITY TITLE RISK
2007-12-15 CVE-2007-6195 Buffer Errors vulnerability in HP Hp-Ux 11.11/11.23
Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request.
network
low complexity
hp CWE-119
critical
10.0
2007-10-09 CVE-2007-5302 Cross-Site Scripting vulnerability in HP Hp-Ux 11.11/11.23/11.31
Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hp CWE-79
4.3
2007-09-20 CVE-2007-5008 Improper Authentication vulnerability in HP Hp-Ux 11.11/11.23/11.31
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
network
low complexity
hp CWE-287
critical
9.0
2007-08-29 CVE-2007-4590 Local Security vulnerability in HP Dynrootdisk, Hp-Ux and Ignite-Ux
The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.
local
hp
3.3
2007-08-08 CVE-2007-4179 Local Denial Of Service vulnerability in HP-UX ARPA Transport
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
local
hp
1.5
2007-08-01 CVE-2007-4125 Remote Denial Of Service vulnerability in HP Hp-Ux 11.11/11.23/11.31
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.
network
hp
7.1
2007-04-30 CVE-2007-2351 Remote Agent Local Privilege Escalation vulnerability in HP Power Manager
Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.
local
low complexity
hp
7.2
2007-04-25 CVE-2007-2246 Resource Management Errors vulnerability in Sendmail 8.11.1/8.9.3
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.
network
low complexity
hp sendmail CWE-399
7.8
2007-03-28 CVE-2007-1727 Remote Unauthorized Access vulnerability in HP OpenView Network Node Manager
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
network
low complexity
hp linux microsoft sun
6.5
2007-02-14 CVE-2007-0916 Local Denial of Service vulnerability in HP Hp-Ux 11.11/11.23
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
local
low complexity
hp
4.9