Back

CVE-2005-3277

The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.

Published: Oct 21, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
hp hp-ux 10.20
hp hp-ux 11.00
hp hp-ux 11.11

GitHub Security Advisory GHSA-wfp6-64v9-pqm2

The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 19.43%

Top 3% most likely to be exploited

Threat Score 45.8 / 100

Data Sources

NVD EPSS GitHub