VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2007-2553May 9, 2007
    risk 0.03cvss —epss 0.01

    Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environment variable.

  • CVE-2007-1882Apr 6, 2007
    risk 0.03cvss —epss 0.06

    qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.

  • CVE-2007-1772Mar 30, 2007
    risk 0.03cvss —epss 0.03

    The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.

  • CVE-2007-0805Feb 7, 2007
    risk 0.03cvss —epss 0.01

    The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.

  • CVE-2007-0161Jan 10, 2007
    risk 0.03cvss —epss 0.01

    The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument,…

  • CVE-2006-5556Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

  • CVE-2006-5557Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to…

  • CVE-2006-1654Apr 6, 2006
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.

  • CVE-2005-1370May 3, 2005
    risk 0.03cvss —epss 0.06

    Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.

  • CVE-2004-2748Dec 31, 2004
    risk 0.03cvss —epss 0.05

    viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.

  • CVE-2004-0492Aug 6, 2004
    risk 0.03cvss —epss 0.34

    Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be…

  • CVE-2003-1461Dec 31, 2003
    risk 0.03cvss —epss 0.02

    Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

  • CVE-2003-1359Dec 31, 2003
    risk 0.03cvss —epss 0.01

    Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

  • CVE-2003-1375Dec 31, 2003
    risk 0.03cvss —epss 0.02

    Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.

  • CVE-2003-1358Dec 31, 2003
    risk 0.03cvss —epss 0.01

    rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

  • CVE-2003-1097Dec 31, 2003
    risk 0.03cvss —epss 0.04

    Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

  • CVE-2003-0089Dec 15, 2003
    risk 0.03cvss —epss 0.01

    Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.

  • CVE-2003-0840Nov 17, 2003
    risk 0.03cvss —epss 0.01

    Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

  • CVE-2002-1473Apr 22, 2003
    risk 0.03cvss —epss 0.04

    Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

  • CVE-2002-1513Apr 2, 2003
    risk 0.03cvss —epss 0.01

    The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

  • CVE-2002-0370Oct 10, 2002
    risk 0.03cvss —epss 0.43

    Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME,…

  • CVE-2002-0991Oct 4, 2002
    risk 0.03cvss —epss 0.02

    Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.

  • CVE-2002-1614Sep 9, 2002
    risk 0.03cvss —epss 0.02

    Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.

  • CVE-2002-1616Aug 1, 2002
    risk 0.03cvss —epss 0.04

    Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.

  • CVE-2002-0250May 29, 2002
    risk 0.03cvss —epss 0.04

    Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration…

  • CVE-2001-0979Sep 3, 2001
    risk 0.03cvss —epss 0.02

    Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.

  • CVE-2001-0208Jun 2, 2001
    risk 0.03cvss —epss 0.01

    MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.

  • CVE-2000-1127Jan 9, 2001
    risk 0.03cvss —epss 0.01

    registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world…

  • CVE-2000-1134Jan 9, 2001
    risk 0.03cvss —epss 0.01

    Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

  • CVE-2000-1028Dec 11, 2000
    risk 0.03cvss —epss 0.01

    Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

  • CVE-2000-0702Oct 20, 2000
    risk 0.03cvss —epss 0.01

    The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.

  • CVE-2000-0636Jul 19, 2000
    risk 0.03cvss —epss 0.04

    HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.

  • CVE-2000-0516Jun 6, 2000
    risk 0.03cvss —epss 0.01

    When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.

  • CVE-2000-0468Jun 2, 2000
    risk 0.03cvss —epss 0.01

    man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.

  • CVE-1999-0693Mar 2, 2000
    risk 0.03cvss —epss 0.01

    Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

  • CVE-2000-0077Jan 2, 2000
    risk 0.03cvss —epss 0.01

    The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

  • CVE-1999-1433Jul 15, 1998
    risk 0.03cvss —epss 0.01

    HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.

  • CVE-1999-0014Jan 21, 1998
    risk 0.03cvss —epss 0.01

    Unauthorized privileged access or denial of service via dtappgather program in CDE.

  • CVE-1999-0306Nov 4, 1997
    risk 0.03cvss —epss 0.02

    buffer overflow in HP xlock program.

  • CVE-1999-0040May 1, 1997
    risk 0.03cvss —epss 0.01

    Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

  • CVE-1999-1408Mar 5, 1997
    risk 0.03cvss —epss 0.01

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

  • CVE-1999-0050Dec 1, 1996
    risk 0.03cvss —epss 0.01

    Buffer overflow in HP-UX newgrp program.

  • CVE-1999-0130Nov 16, 1996
    risk 0.03cvss —epss 0.01

    Local users can start Sendmail in daemon mode and gain root privileges.

  • CVE-2015-6946Sep 15, 2015
    risk 0.02cvss —epss 0.21

    Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit…

  • CVE-2014-2626Jul 26, 2014
    risk 0.02cvss —epss 0.19

    Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

  • CVE-2012-0127Mar 31, 2012
    risk 0.02cvss —epss 0.24

    Unspecified vulnerability in HP Performance Manager 9.00 allows remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2011-1867Jul 11, 2011
    risk 0.02cvss —epss 0.26

    Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to…

  • CVE-2011-1732May 7, 2011
    risk 0.02cvss —epss 0.25

    Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed stutil message.

  • CVE-2009-4000Jan 20, 2010
    risk 0.02cvss —epss 0.20

    Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.

  • CVE-2009-3845Dec 10, 2009
    risk 0.02cvss —epss 0.22

    The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter to unspecified Perl scripts.

Page 34 of 56