Vulnerabilities > HP

DATE CVE VULNERABILITY TITLE RISK
2002-05-31 CVE-2002-0279 Unspecified vulnerability in HP Hp-Ux 11.11
The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.
local
low complexity
hp
4.6
2002-05-29 CVE-2002-0250 Authentication Bypass vulnerability in HP AdvanceStack Switch
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.
network
low complexity
hp
7.5
2002-03-19 CVE-2002-0076 Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.
network
low complexity
hp microsoft sun
7.5
2002-01-11 CVE-2003-0061 Local Security vulnerability in HP Hp-Ux 10.20
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
local
low complexity
hp
7.2
2001-12-31 CVE-2001-1564 Unspecified vulnerability in HP Hp-Ux
setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available disk space.
local
low complexity
hp
2.1
2001-12-31 CVE-2001-1563 Remote Security vulnerability in Tomcat
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources.
network
low complexity
apache hp
7.5
2001-12-31 CVE-2001-1509 Unspecified vulnerability in HP Hp-Ux 11.20
geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.
local
low complexity
hp
4.6
2001-12-31 CVE-2001-1506 Unspecified vulnerability in HP Secure OS 1.0
Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.
local
low complexity
hp
4.6
2001-12-15 CVE-2001-1198 Unspecified vulnerability in HP Hp-Ux
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
local
low complexity
hp
7.2
2001-12-12 CVE-2001-0797 Buffer Overflow vulnerability in Multiple Vendor System V Derived 'login'
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
network
low complexity
sgi hp ibm sco sun
critical
10.0