Hpux

Vendor:

First CVE: Jan 13, 1993 · Active for 33 years

481
Total CVEs
More Total CVEs than 64% of tracked products
14.6
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.2%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hpux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 1993
33 years ago
Most Recent CVE
Aug 14, 2025
344 days ago

CVE Severity & Scoring

Hpux481 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local28 (5.8%)
Network114 (23.7%)
Unknown339 (70.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low132 (27.4%)
High10 (2.1%)
Unknown339 (70.5%)
User Interaction
None121 (25.2%)
Unknown339 (70.5%)
Required21 (4.4%)
Privileges Required
Low69 (14.3%)
High7 (1.5%)
None66 (13.7%)
Unknown339 (70.5%)

Top CVEs

Signals from CVEs in this product scope (481 CVEs).

481 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC
Jul 7, 200010.089NOYES
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to
May 5, 200310.088NOYES
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.088NOYES
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause
Sep 28, 20167.587NOYES
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
Land IP denial of service.
Dec 1, 19975.079NOYES
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi
May 21, 20153.776NOYES
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
A Unix account has a default, null, blank, or missing password.
Mar 1, 19987.572NOYES

Exploit Exposure

Signals from CVEs in this product scope (481 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· Bottom 1%
Metasploit
11 CVEs
2.3% of CVEs· Bottom 1%
Nuclei
1 CVE
0.2% of CVEs· Bottom 1%
ExploitDB
61 CVEs
12.7% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (481 CVEs).

Media Mentions

Signals from CVEs in this product scope (481 CVEs).

Top CNAs Publishing CVEs For Hpux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
b.11.31246.614.1%12
b.11.23207.510.5%12
b.11.2215.154.9%01
b.11.11157.36.8%01
b.11.0027.231.4%01
9.1057.81.7%03
9.0947.91.8%02
9.0847.91.8%02
9.0766.923.1%04
9.0647.91.8%02
9.0586.217.5%05
9.0476.819.9%04
9.0356.927.5%03
9.0186.717.5%05
9.0096.715.7%05
9196.41.1%00
8.0917.20.5%00
8.0817.20.5%00
8.0717.20.5%00
8.0625.90.5%00