Vulnerabilities > HP > High

DATE CVE VULNERABILITY TITLE RISK
2007-02-23 CVE-2007-1086 Local Privilege Escalation vulnerability in IBM DB2 Universal Database
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
local
low complexity
hp ibm linux microsoft sun
7.2
2007-02-23 CVE-2006-7034 SQL-Injection vulnerability in Super Link Exchange Script Super Link Exchange Script 1.0
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
7.5
2007-02-21 CVE-2007-1043 Authentication Bypass vulnerability in Ezboo Webstats 3.0.3
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
7.5
2007-02-08 CVE-2007-0819 Unspecified vulnerability in HP Network Node Manager 7.5
HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.
local
low complexity
hp
7.2
2007-01-19 CVE-2007-0396 Remote Denial Of Service vulnerability in HP Hp-Ux 11.23
Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.
network
hp
7.1
2007-01-19 CVE-2007-0358 Denial Of Service vulnerability in HP Jetdirect
Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.
network
low complexity
hp
7.8
2007-01-09 CVE-2007-0139 Remote Security vulnerability in HP Openvms 7.3/7.32
Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.
network
low complexity
hp
7.5
2006-12-26 CVE-2006-6742 Denial-Of-Service vulnerability in HP FTP Print Server, Laserjet 5000 and Laserjet 5100
Multiple buffer overflows in FTP Print Server 2.4 and 2.4.5 in HP LaserJet 5000 Series printers with firmware R.25.15 or R.25.47, and HP LaserJet 5100 Series printers with firmware V.29.12, allow remote attackers to cause a denial of service (device crash) via a long string in the (1) LIST or (2) NLST command.
network
low complexity
hp
7.8
2006-12-18 CVE-2006-6608 Remote Unauthorized Access vulnerability in HP products
Unspecified vulnerability in SSH key based authentication in HP Integrated Lights Out (iLO) 1.70 through 1.87, and iLO 2 1.00 through 1.11, on Proliant servers, allows remote attackers to "gain unauthorized access."
network
low complexity
hp
7.5
2006-12-10 CVE-2006-6418 Buffer Errors vulnerability in HP Tru64 4.0F/4.0G/5.1A
Buffer overflow in the POSIX Threads library (libpthread) on HP Tru64 UNIX 4.0F PK8, 4.0G PK4, and 5.1A PK6 allows local users to gain root privileges via a long PTHREAD_CONFIG environment variable.
local
low complexity
hp CWE-119
7.2