Vulnerabilities > HP > High

DATE CVE VULNERABILITY TITLE RISK
2003-05-12 CVE-2003-0221 Unspecified vulnerability in HP Tru64 5.1B
The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.
local
low complexity
hp
7.2
2003-04-11 CVE-2002-1426 Denial Of Service vulnerability in HP Procurve Switch 4000M C.07.23
HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.
network
low complexity
hp
7.8
2003-04-11 CVE-2002-1408 Unspecified vulnerability in HP Openview Emanate Snmp Agent and Vvos
Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.
network
low complexity
hp
7.5
2003-04-11 CVE-2002-1406 Local Passwd vulnerability in HP Hp-Ux 11.04
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
local
low complexity
hp
7.2
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2003-03-03 CVE-2003-0064 The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g.
network
low complexity
sgi hp ibm sun
7.5
2002-12-31 CVE-2002-2363 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 11.00
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
local
low complexity
hp CWE-264
7.2
2002-12-31 CVE-2002-1796 Improper Verification of Cryptographic Signature vulnerability in HP Chaivm Ezloader
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.
local
low complexity
hp CWE-347
7.8
2002-12-31 CVE-2002-1617 Unspecified vulnerability in HP Tru64 5.1Bpk2Bl22
Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.
local
low complexity
hp
7.2
2002-12-11 CVE-2002-1317 Remote Buffer Overrun vulnerability in Multiple Vendor X Font Server
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
network
low complexity
xfree86-project sgi hp sun
7.5