CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1288  CVE-1999-1308  Candidate  Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:hp-large-uid-gid(7594)  View
1291  CVE-1999-1311  Candidate  Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:hp-dt-bypass-auth(7668) | ACKNOWLEDGED-BY-VENDOR  View
2597  CVE-2000-1028  Candidate  Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.  Modified (20010119-01)  ACCEPT(1) Mell | MODIFY(1) Frech | NOOP(2) Cole, Renaud  Frech> XF:hp-cu-bo(5460)  View
3420  CVE-2001-0607  Candidate  asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.  Modified (20090302)  ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:hp-asecure-dos(6212) | Possible duplicate of CVE-2000-0083: HP asecure creates the | Audio Security File audio.sec with insecure permissions, which allows | local users to cause a denial of service or gain additional | privileges. | Williams> Frech - this is not a dupe of CVE-2000-0083. | Christey> While this advisory is vaguely worded, the fact that HP did an | advisory for the other asecure problem (now CVE-2000-0083) | indicates at the very least that this problem occurs in | a different version than CVE-2000-0083, so CD:SF-LOC | suggests a SPLIT. However, the HP advisory says "10.X" | and "11.X" are affected, so who knows what versions they | *really* mean? | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3421  CVE-2001-0608  Candidate  HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program.  Modified (20020225-01)  ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:hp-aif-gain-privileges(6951)  View

Page 168 of 20943, showing 5 records out of 104715 total, starting on record 836, ending on 840

Actions