Where
AND
-Infinity
0
Severity
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P

Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.

First published (updated )
Severity
6.2
AV:L/AC:L/Au:S/C:C/I:C/A:N

Unspecified vulnerability in m4 in HP HP-UX B.11.23 and B.11.31 allows local users to obtain sensitive information or modify data via unknown vectors.

First published (updated )
Severity
4.6
Buffer Overflow
AV:L/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.

First published (updated )
Severity
6.2
AV:L/AC:H/Au:N/C:C/I:C/A:C

HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Denial of service in HP-UX SharedX recserv program.

First published (updated )
Severity
4.6
Buffer Overflow
AV:L/AC:L/Au:N/C:P/I:P/A:P

Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

ftp on HP-UX 11.00 allows local users to gain privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability in HP-UX mediainit program.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

HP-UX gwind program allows users to modify arbitrary files.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

HP ypbind allows attackers with root privileges to modify NIS data.

First published (updated )
Severity
6.2
AV:L/AC:L/Au:S/C:C/I:C/A:N

Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors.

First published (updated )
Severity
4.4
AV:L/AC:M/Au:S/C:N/I:N/A:C

Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203