Hpux
Vendor:
First CVE: Jan 13, 1993 · Active for 33 years
481
Total CVEs
More Total CVEs than 64% of tracked products
14.6
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.2%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hpux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 1993
33 years ago
Most Recent CVE
Aug 14, 2025
344 days ago
CVE Severity & Scoring
Hpux481 CVEs
8%
43%
46%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (5.8%)
Network114 (23.7%)
Unknown339 (70.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low132 (27.4%)
High10 (2.1%)
Unknown339 (70.5%)
User Interaction
None121 (25.2%)
Unknown339 (70.5%)
Required21 (4.4%)
Privileges Required
Low69 (14.3%)
High7 (1.5%)
None66 (13.7%)
Unknown339 (70.5%)
Top CVEs
Signals from CVEs in this product scope (481 CVEs).
481 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2000-0573HIGH The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC | Jul 7, 2000 | 10.0 | 89 | NO | YES |
CVE-2003-0201HIGH Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to | May 5, 2003 | 10.0 | 88 | NO | YES |
CVE-2001-0797HIGH Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as | Dec 12, 2001 | 10.0 | 88 | NO | YES |
CVE-2016-2776HIGH buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause | Sep 28, 2016 | 7.5 | 87 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-1999-0016MEDIUM Land IP denial of service. | Dec 1, 1997 | 5.0 | 79 | NO | YES |
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-1999-0502HIGH A Unix account has a default, null, blank, or missing password. | Mar 1, 1998 | 7.5 | 72 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (481 CVEs).
CISA KEV
1 CVE
0.2% of CVEs· Bottom 1%
Metasploit
11 CVEs
2.3% of CVEs· Bottom 1%
Nuclei
1 CVE
0.2% of CVEs· Bottom 1%
ExploitDB
61 CVEs
12.7% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (481 CVEs).
Media Mentions
Signals from CVEs in this product scope (481 CVEs).
Top CNAs Publishing CVEs For Hpux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| b.11.31 | 24 | 6.6 | 14.1% | 1 | 2 |
| b.11.23 | 20 | 7.5 | 10.5% | 1 | 2 |
| b.11.22 | 1 | 5.1 | 54.9% | 0 | 1 |
| b.11.11 | 15 | 7.3 | 6.8% | 0 | 1 |
| b.11.00 | 2 | 7.2 | 31.4% | 0 | 1 |
| 9.10 | 5 | 7.8 | 1.7% | 0 | 3 |
| 9.09 | 4 | 7.9 | 1.8% | 0 | 2 |
| 9.08 | 4 | 7.9 | 1.8% | 0 | 2 |
| 9.07 | 6 | 6.9 | 23.1% | 0 | 4 |
| 9.06 | 4 | 7.9 | 1.8% | 0 | 2 |
| 9.05 | 8 | 6.2 | 17.5% | 0 | 5 |
| 9.04 | 7 | 6.8 | 19.9% | 0 | 4 |
| 9.03 | 5 | 6.9 | 27.5% | 0 | 3 |
| 9.01 | 8 | 6.7 | 17.5% | 0 | 5 |
| 9.00 | 9 | 6.7 | 15.7% | 0 | 5 |
| 9 | 19 | 6.4 | 1.1% | 0 | 0 |
| 8.09 | 1 | 7.2 | 0.5% | 0 | 0 |
| 8.08 | 1 | 7.2 | 0.5% | 0 | 0 |
| 8.07 | 1 | 7.2 | 0.5% | 0 | 0 |
| 8.06 | 2 | 5.9 | 0.5% | 0 | 0 |