Vulnerabilities > HP > HP UX

DATE CVE VULNERABILITY TITLE RISK
2005-11-16 CVE-2005-3564 Local Privilege Escalation vulnerability in HP-UX ENVD
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.
local
low complexity
hp
7.2
2005-10-23 CVE-2005-3296 The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.
network
low complexity
hp
critical
10.0
2005-10-23 CVE-2005-3295 Local Denial Of Service vulnerability in HP Hp-Ux 11.23
Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."
local
low complexity
hp
2.1
2005-10-21 CVE-2005-3277 Unspecified vulnerability in HP Hp-Ux 10.20/11.00/11.11
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
network
low complexity
hp
critical
10.0
2005-09-20 CVE-2005-2993 Remote Denial Of Service vulnerability in HP-UX FTPD
Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).
local
low complexity
hp
1.7
2005-05-31 CVE-2005-1771 Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.
network
low complexity
hp
7.5
2005-05-02 CVE-2005-1192 Remote Denial Of Service vulnerability in HP-UX ICMP PMTUD
Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.
network
low complexity
hp
5.0
2005-03-01 CVE-2004-1029 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
network
hp sun symantec conectiva gentoo CWE-264
critical
9.3
2005-02-24 CVE-2005-0547 Restricted File Access vulnerability in HP-UX FTP Server
Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."
local
low complexity
hp
4.6
2005-02-10 CVE-2005-0364 Denial-Of-Service vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.
network
low complexity
hp
5.0