Compaq's vulnerability profile centers on a modest portfolio of infrastructure and management products including Tru64, various management agents, and Insight Manager components that address systems administration and monitoring functions. The recurring weakness classes cluster around authentication and input-handling issues—improper authentication mechanisms, cross-site scripting flaws, and insufficient rate-limiting on authentication attempts—reflecting the web-facing and access-control demands of administrative interfaces. Notably, vulnerabilities in this vendor's products have frequently acquired public exploit code, consistent with the high-value nature of systems-management and remote-access tools as targets for infrastructure compromise. Defenders should prioritize inventory and patching of affected management agent and platform components, particularly in network-facing deployments where authentication weaknesses carry elevated risk; live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Compaq over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-1209HIGH The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that | Aug 12, 2002 | 10.0 | 89 | NO | YES |
CVE-2003-0201HIGH Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to | May 5, 2003 | 10.0 | 88 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2003-0161HIGH The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length | Apr 2, 2003 | 10.0 | 63 | NO | YES |
CVE-2002-0679HIGH Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREA | Sep 5, 2002 | 10.0 | 42 | NO | NO |
CVE-2003-0196HIGH Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different | May 5, 2003 | 10.0 | 35 | NO | NO |
CVE-2002-2002HIGH Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables. | Dec 31, 2002 | 7.5 | 33 | NO | NO |
CVE-2001-1093HIGH Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument. | Sep 10, 2001 | 7.2 | 29 | NO | YES |
CVE-2001-0840HIGH Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI. | Dec 6, 2001 | 10.0 | 28 | NO | NO |
CVE-2002-2422MEDIUM Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL | Dec 31, 2002 | 4.3 | 27 | NO | YES |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Compaq.
Media articles that mention a CVE ID that affects a product developed by Compaq — matched by CVE ID, not by vendor name.