CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1288 | CVE-1999-1308 | Candidate | Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges. | Modified (20020218-01) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | Frech> XF:hp-large-uid-gid(7594) | View |
1291 | CVE-1999-1311 | Candidate | Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges. | Proposed (20010912) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | Frech> XF:hp-dt-bypass-auth(7668) | ACKNOWLEDGED-BY-VENDOR | View |
2597 | CVE-2000-1028 | Candidate | Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument. | Modified (20010119-01) | ACCEPT(1) Mell | MODIFY(1) Frech | NOOP(2) Cole, Renaud | Frech> XF:hp-cu-bo(5460) | View |
3420 | CVE-2001-0607 | Candidate | asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083. | Modified (20090302) | ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey | Frech> XF:hp-asecure-dos(6212) | Possible duplicate of CVE-2000-0083: HP asecure creates the | Audio Security File audio.sec with insecure permissions, which allows | local users to cause a denial of service or gain additional | privileges. | Williams> Frech - this is not a dupe of CVE-2000-0083. | Christey> While this advisory is vaguely worded, the fact that HP did an | advisory for the other asecure problem (now CVE-2000-0083) | indicates at the very least that this problem occurs in | a different version than CVE-2000-0083, so CD:SF-LOC | suggests a SPLIT. However, the HP advisory says "10.X" | and "11.X" are affected, so who knows what versions they | *really* mean? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
3421 | CVE-2001-0608 | Candidate | HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program. | Modified (20020225-01) | ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:hp-aif-gain-privileges(6951) | View |
Page 168 of 20943, showing 5 records out of 104715 total, starting on record 836, ending on 840