Vulnerabilities > HP > HP UX > 11.23

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-0952 Unspecified vulnerability in HP Hp-Ux
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.
network
low complexity
hp
6.4
2004-12-31 CVE-2004-0826 Remote Heap Overflow vulnerability in Mozilla Network Security Services Library
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
network
low complexity
mozilla netscape sun hp
7.5
2004-12-23 CVE-2004-1375 Privilege Escalation vulnerability in HP-UX System Administration Manager
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.
local
low complexity
hp
4.6
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0
2004-11-23 CVE-2004-0079 NULL Pointer Dereference vulnerability in multiple products
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
7.5
2003-12-15 CVE-2003-0951 Remote Security vulnerability in HP Hp-Ux 11.23
Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.
network
low complexity
hp
7.5