Vulnerabilities > HP > High

DATE CVE VULNERABILITY TITLE RISK
2007-09-18 CVE-2007-4938 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
7.6
2007-08-01 CVE-2007-4125 Remote Denial Of Service vulnerability in HP Hp-Ux 11.11/11.23/11.31
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.
network
hp
7.1
2007-07-04 CVE-2007-3554 Buffer Overflow vulnerability in HP Instant Support ActiveX Control Driver Check
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.
network
high complexity
hp
7.6
2007-05-14 CVE-2007-2656 Buffer Overflow vulnerability in HP Hpqvwocx.Dll 1.0.0.309
Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote attackers to cause a denial of service (application crash) and possibly have other impact via a long argument to the DeleteProfile method.
network
low complexity
hp
7.8
2007-05-09 CVE-2007-2553 Local Privilege Escalation vulnerability in HP Tru64 5.1A/5.1B3/5.1B4
Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.
local
low complexity
hp
7.2
2007-05-04 CVE-2007-2502 Denial of Service vulnerability in HP ProCurve 9300m Switches
Unspecified vulnerability in HP ProCurve 9300m Series switches with software 08.0.01c through 08.0.01j allows remote attackers to cause a denial of service via unknown vectors, a different switch series than CVE-2006-4015.
network
low complexity
hp
7.8
2007-04-30 CVE-2007-2351 Remote Agent Local Privilege Escalation vulnerability in HP Power Manager
Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.
local
low complexity
hp
7.2
2007-04-25 CVE-2007-2246 Resource Management Errors vulnerability in Sendmail 8.11.1/8.9.3
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.
network
low complexity
hp sendmail CWE-399
7.8
2007-04-11 CVE-2007-1945 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
network
low complexity
hp ibm linux microsoft sun
7.5
2007-03-30 CVE-2007-1772 Denial Of Service vulnerability in HP Jetdirect FTP Print Server RERT Command
The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.
network
hp
7.1