Vulnerabilities > HP > HP UX

DATE CVE VULNERABILITY TITLE RISK
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2003-03-03 CVE-2003-0064 The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g.
network
low complexity
sgi hp ibm sun
7.5
2002-12-31 CVE-2002-2363 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 11.00
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
local
low complexity
hp CWE-264
7.2
2002-12-31 CVE-2002-2270 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 10.10/10.20/11.00
Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.
local
low complexity
hp CWE-264
3.6
2002-12-31 CVE-2002-2263 Configuration vulnerability in HP Visualize Conference FTP B.11.00.11
The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files.
local
low complexity
hp CWE-16
6.6
2002-12-31 CVE-2002-2262 Denial Of Service vulnerability in HP-UX xntpd
Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.
network
low complexity
hp
5.0
2002-12-31 CVE-2002-2138 Denial Of Service vulnerability in HP Advanced Server 9000 and Hp-Ux
RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139.
network
low complexity
hp
5.0
2002-12-31 CVE-2002-1794 Privilege Escalation vulnerability in HP-UX LDAP-UX Integration Pam-Authz
Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.
network
low complexity
hp
critical
10.0
2002-12-31 CVE-2002-1668 Denial of Service vulnerability in HP Hp-Ux, Hp-Ux Series 700 and Hp-Ux Series 800
HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.
local
low complexity
hp
2.1
2002-12-11 CVE-2002-1317 Remote Buffer Overrun vulnerability in Multiple Vendor X Font Server
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
network
low complexity
xfree86-project sgi hp sun
7.5