Vulnerabilities > HP

DATE CVE VULNERABILITY TITLE RISK
2003-04-11 CVE-2002-1408 Unspecified vulnerability in HP Openview Emanate Snmp Agent and Vvos
Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.
network
low complexity
hp
7.5
2003-04-11 CVE-2002-1406 Local Passwd vulnerability in HP Hp-Ux 11.04
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
local
low complexity
hp
7.2
2003-04-02 CVE-2003-0161 The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
network
low complexity
sendmail compaq hp sun
critical
10.0
2003-03-31 CVE-2003-0085 Buffer Overflow vulnerability in Samba SMB/CIFS Packet Assembling
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
network
low complexity
samba hp
critical
10.0
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2003-03-03 CVE-2003-0064 The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g.
network
low complexity
sgi hp ibm sun
7.5
2002-12-31 CVE-2002-2363 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 11.00
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
local
low complexity
hp CWE-264
7.2
2002-12-31 CVE-2002-2270 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 10.10/10.20/11.00
Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.
local
low complexity
hp CWE-264
3.6
2002-12-31 CVE-2002-2265 Permissions, Privileges, and Access Controls vulnerability in Open Source Internet Solutions Open Source Internet Solutions 5.4
Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.
network
low complexity
hp open-source-internet-solutions CWE-264
6.4
2002-12-31 CVE-2002-2264 Denial-Of-Service vulnerability in Secure Web Server For Tru64 4.0/5.0/5.1
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors.
network
low complexity
hp
critical
10.0