HP
Hp-ux: vulnerabilidades y CVE
Hp-ux tiene 291 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE291
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2012-1823 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2012 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-30903 | Media (5.5) | 0.18% | — | 16 jun 2023 | HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. |
| CVE-2018-5740 | Alta (7.5) | 60% | — | 16 ene 2019 | "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers.… |
| CVE-2016-2776 | Alta (7.5) | 89% | — | 28 sept 2016 | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure… |
| CVE-2016-2775 | Media (5.9) | 63% | — | 19 jul 2016 | ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request… |
| CVE-2015-2126 | Alta (7.2) | 0.56% | — | 6 jul 2015 | Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions. |
| CVE-2015-4000 | Baja (3.7) | 100% | — | 21 may 2015 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct… |
| CVE-2014-7879 | Alta (8.5) | 4.7% | — | 10 dic 2014 | HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors. |
| CVE-2014-7877 | Media (4.9) | 0.61% | — | 30 oct 2014 | Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors. |
| CVE-2014-7874 | Media (6.8) | 1.6% | — | 19 oct 2014 | Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of… |
| CVE-2014-2490 | Alta (9.3) | 6.1% | — | 17 jul 2014 | Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. |
| CVE-2013-6209 | Media (4.3) | 2.7% | — | 14 mar 2014 | Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors. |
| CVE-2013-6200 | Media (6.2) | 0.37% | — | 11 mar 2014 | Unspecified vulnerability in m4 in HP HP-UX B.11.23 and B.11.31 allows local users to obtain sensitive information or modify data via unknown vectors. |
| CVE-2013-4854 | Alta (7.8) | 34% | — | 29 jul 2013 | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to… |
| CVE-2012-1823 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 may 2012 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote… |
| CVE-2012-0131 | Alta (10) | 7.4% | — | 5 abr 2012 | Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
| CVE-2012-0126 | Media (5.8) | 1.8% | — | 28 mar 2012 | Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125. |
| CVE-2012-0125 | Baja (3.3) | 0.44% | — | 28 mar 2012 | Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126. |
| CVE-2011-2398 | Media (6.8) | 0.31% | — | 11 jul 2011 | Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges or cause a denial of service via unknown vectors. |
| CVE-2011-0896 | Media (6.8) | 2.9% | — | 15 abr 2011 | Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors. |
| CVE-2011-0891 | Media (4.4) | 0.28% | — | 4 abr 2011 | Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors. |
| CVE-2010-4108 | Media (6.8) | 2.6% | — | 8 dic 2010 | HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows remote authenticated users to cause a denial of service via unspecified vectors. |
| CVE-2010-2712 | Media (6.8) | 0.33% | — | 30 ago 2010 | Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors. |
| CVE-2010-1032 | Media (4.9) | 0.53% | — | 21 abr 2010 | Unspecified vulnerability in HP HP-UX B.11.11 allows local users to cause a denial of service via unknown vectors. |
| CVE-2010-1030 | Media (4.4) | 0.29% | — | 31 mar 2010 | Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors. |
| CVE-2010-0451 | Media (4) | 3.2% | — | 29 mar 2010 | The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests. |
| CVE-2009-2679 | Alta (7.8) | 4.1% | — | 5 oct 2009 | Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors. |
| CVE-2009-2682 | Alta (7.2) | 0.54% | — | 24 sept 2009 | Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors. |
| CVE-2009-0719 | Media (6) | 0.29% | — | 29 abr 2009 | Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660. |
| CVE-2009-0207 | Media (6.8) | 0.30% | — | 25 mar 2009 | Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31… |
| CVE-2009-0418 | Alta (9.3) | 8.2% | — | 4 feb 2009 | The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de HP
Intelligent Management Center · 310Openview Network Node Manager · 80System Management Homepage · 78Instantos · 56XP7 Command View · 53Systems Insight Manager · 50Matrix Operating Environment · 34Tru64 · 32Network Node Manager I · 29Elite X2 G4 Firmware · 28Elitebook 830 G6 Firmware · 28Loadrunner · 28