Product

Hp Ux 10.09


View All Versions

Vulnerability History

Weakness Analysis

Related Vulnerabilities

Vulnerability Severity Score Release Date Summary
CVE-2003-1358 7.2 Dec. 31, 2003

rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

CVE-2003-1359 7.2 Dec. 31, 2003

Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

CVE-2003-1360 7.2 Dec. 31, 2003

Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.

CVE-1999-0046 10.0 Feb. 6, 1997

Buffer overflow of rlogin program using TERM environmental variable.

CVE-1999-0040 7.2 May 1, 1997

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

CVE-2000-0005 7.2 Jan. 2, 1999

HP-UX aserver program allows local users to gain privileges via a symlink attack.

CVE-2002-2262 5.0 Dec. 31, 2002

Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.

CVE-1999-0057 7.5 Nov. 16, 1998

Vacation program allows command execution by remote users through a sendmail command.

CVE-2003-0161 10.0 April 2, 2003

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Followers