Vulnerabilities > HP

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-1668 Denial of Service vulnerability in HP Hp-Ux, Hp-Ux Series 700 and Hp-Ux Series 800
HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.
local
low complexity
hp
2.1
2002-12-31 CVE-2002-1617 Unspecified vulnerability in HP Tru64 5.1Bpk2Bl22
Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.
local
low complexity
hp
7.2
2002-12-11 CVE-2002-1318 Buffer Overrun vulnerability in Samba Server Encrypted Password
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.
network
low complexity
samba sgi hp
critical
10.0
2002-12-11 CVE-2002-1317 Remote Buffer Overrun vulnerability in Multiple Vendor X Font Server
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
network
low complexity
xfree86-project sgi hp sun
7.5
2002-11-12 CVE-2002-0711 Denial of Service vulnerability in HP Trucluster Server 5.0A/5.1/5.1A
Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.
network
low complexity
hp
5.0
2002-11-04 CVE-2002-1232 Remote Network Information Leakage vulnerability in YPServ
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
network
low complexity
debian hp redhat
5.0
2002-10-28 CVE-2002-0836 dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
network
low complexity
hp mandrakesoft redhat
7.5
2002-10-16 CVE-2002-1618 Unspecified vulnerability in HP Hp-Ux and JFS
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.
local
low complexity
hp
7.2
2002-10-11 CVE-2002-1147 Denial Of Service vulnerability in HP Procurve 4000M Switch Device Reset
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.
network
hp
7.1
2002-10-04 CVE-2002-1134 Unspecified vulnerability in HP Webes Service Tools 2.0/3.1/4.0
Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.
network
low complexity
hp
5.0