Technology · Hp
HP-UX vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 38 vulnerabilities in HP-UX: 0 in the last 7 days and 0 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-1999-0016, was published on 1 December 1997.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 4
- Exploited in the wild
- 0
About HP-UX
HP-UX is Hewlett Packard Enterprise's proprietary implementation of the Unix operating system.
Latest HP-UX vulnerabilities
- CVE-1999-0016: Multiple Vendors TCP/IP Land denial of servicemediumCVSS 5
- CVE-1999-0210: Sun Solaris automountd command injection via shell metacharacterscriticalCVSS 10
- CVE-1999-0216: Linux inetd denial of service via SYN and RST packetsmediumCVSS 5
- CVE-1999-0326: HP HP-UX vulnerability in mediainitmediumCVSS 4.6
- CVE-1999-1213: HP HP-UX denial of service in telnet servicemediumCVSS 5
- CVE-1999-1133: HP HP-UX privilege escalation in X Windows utilitiesmediumCVSS 4.6
- CVE-1999-1139: HP HP-UX arbitrary file overwrite in CUE via symlink attackhighCVSS 7.2
- CVE-1999-0524: Multiple Vendors ICMP Information Disclosure via Netmask and Timestamp RequestslowCVSS 2.1
- CVE-1999-1308: HP HP-UX privilege escalation via large UID or GIDmediumCVSS 4.6
- CVE-1999-0962: HP HP-UX buffer overflow in passwd commandhighCVSS 7.2
- CVE-1999-1408: IBM AIX and HP-UX denial of service via socket reuselowCVSS 2.1
- CVE-1999-0046: Multiple Vendors rlogin buffer overflow via TERM environment variablecriticalCVSS 10
- CVE-1999-1160: HP HP-UX privilege escalation in ftpd and kftpdcriticalCVSS 10
- CVE-1999-0309: HP HP-UX privilege escalation in vgdisplayhighCVSS 7.2
- CVE-1999-1088: HP HP-UX privilege escalation in chsh commandhighCVSS 7.2
- CVE-1999-1311: HP HP-UX authentication bypass in dtlogin and dtsessionmediumCVSS 4.6
- CVE-1999-1249: HP HP-UX privilege escalation in movemailmediumCVSS 4.6
- CVE-1999-1251: HP HP-UX denial of service in direct audio user space codelowCVSS 2.1
- CVE-1999-0127: HP HP-UX arbitrary file overwrite in swinstall and swmodifyhighCVSS 7.2
- CVE-1999-1089: HP HP-UX buffer overflow in chfn commandhighCVSS 7.2
- CVE-1999-0050: HP HP-UX buffer overflow in newgrphighCVSS 7.2
- CVE-1999-1161: HP HP-UX privilege escalation in ppl via core dumphighCVSS 7.2
- CVE-1999-0336: HP HP-UX buffer overflow in mstmhighCVSS 7.2
- CVE-1999-0311: HP HP-UX privilege escalation in fpkg2swpkhighCVSS 7.2
- CVE-1999-0246: HP Remote Watch remote root access vulnerabilitycriticalCVSS 10
Most severe HP-UX vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-1999-0210: Sun Solaris automountd command injection via shell metacharacterscriticalCVSS 10
- CVE-1999-0046: Multiple Vendors rlogin buffer overflow via TERM environment variablecriticalCVSS 10
- CVE-1999-1160: HP HP-UX privilege escalation in ftpd and kftpdcriticalCVSS 10
- CVE-1999-0246: HP Remote Watch remote root access vulnerabilitycriticalCVSS 10
- CVE-1999-1139: HP HP-UX arbitrary file overwrite in CUE via symlink attackhighCVSS 7.2
- CVE-1999-0962: HP HP-UX buffer overflow in passwd commandhighCVSS 7.2
- CVE-1999-0309: HP HP-UX privilege escalation in vgdisplayhighCVSS 7.2
- CVE-1999-1088: HP HP-UX privilege escalation in chsh commandhighCVSS 7.2
- CVE-1999-0127: HP HP-UX arbitrary file overwrite in swinstall and swmodifyhighCVSS 7.2
- CVE-1999-1089: HP HP-UX buffer overflow in chfn commandhighCVSS 7.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/hp-ux.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "HP-UX vulnerabilities", https://junglewise.ai/threats/technologies/hp-ux, 26 September 2026.