Vulnerabilities > HP > Critical

DATE CVE VULNERABILITY TITLE RISK
2005-12-08 CVE-2005-4090 IPSec Unauthorized Remote Access vulnerability in HP-UX
Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.
network
low complexity
hp
critical
10.0
2005-10-23 CVE-2005-3296 The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.
network
low complexity
hp
critical
10.0
2005-10-21 CVE-2005-3277 Unspecified vulnerability in HP Hp-Ux 10.20/11.00/11.11
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
network
low complexity
hp
critical
10.0
2005-03-01 CVE-2004-1029 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
network
hp sun symantec conectiva gentoo CWE-264
critical
9.3
2005-01-10 CVE-2004-0993 Remote Buffer Overflow vulnerability in HP HPSockd 0.4/0.5
Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.
network
low complexity
hp
critical
10.0
2004-12-31 CVE-2004-1486 Remote vulnerability in HP ServiceGuard Undisclosed
Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.
network
low complexity
hp
critical
10.0
2004-08-06 CVE-2004-0716 Remote Security vulnerability in HP Hp-Ux 11
Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.
network
low complexity
hp
critical
10.0
2003-12-31 CVE-2003-1496 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Tru64
Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors.
network
low complexity
hp CWE-119
critical
10.0
2003-12-31 CVE-2003-1495 Permissions, Privileges, and Access Controls vulnerability in HP products
Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.
network
low complexity
hp CWE-264
critical
10.0
2003-10-06 CVE-2003-0694 The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
network
low complexity
sendmail sgi apple compaq freebsd gentoo hp ibm netbsd sun turbolinux
critical
10.0