Aix
by IBM
CVEs (409)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-0978 | 0.00 | — | 0.00 | Feb 16, 2007 | Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data. | |||
| CVE-2007-0670 | 0.00 | — | 0.00 | Feb 3, 2007 | Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin. | |||
| CVE-2007-0618 | 0.00 | — | 0.02 | Jan 31, 2007 | Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability." | |||
| CVE-2007-0392 | 0.00 | — | 0.00 | Jan 19, 2007 | IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572. | |||
| CVE-2006-6915 | 0.00 | — | 0.01 | Dec 31, 2006 | ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources. | |||
| CVE-2006-6914 | 0.00 | — | 0.02 | Dec 31, 2006 | Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors. | |||
| CVE-2006-5008 | 0.00 | — | 0.03 | Sep 27, 2006 | Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors. | |||
| CVE-2006-5003 | 0.00 | — | 0.00 | Sep 27, 2006 | Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors. | |||
| CVE-2006-5004 | 0.00 | — | 0.00 | Sep 27, 2006 | Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors. | |||
| CVE-2006-5010 | 0.00 | — | 0.00 | Sep 27, 2006 | Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program. | |||
| CVE-2006-5006 | 0.00 | — | 0.00 | Sep 27, 2006 | Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument. | |||
| CVE-2006-5005 | 0.00 | — | 0.00 | Sep 27, 2006 | Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login. | |||
| CVE-2006-5007 | 0.00 | — | 0.00 | Sep 27, 2006 | Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux. | |||
| CVE-2006-5011 | 0.00 | — | 0.00 | Sep 27, 2006 | Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine". | |||
| CVE-2006-5009 | 0.00 | — | 0.00 | Sep 27, 2006 | Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow. | |||
| CVE-2006-4522 | 0.00 | — | 0.00 | Sep 1, 2006 | Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors. | |||
| CVE-2006-4416 | 0.00 | — | 0.00 | Aug 28, 2006 | Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program. | |||
| CVE-2006-2647 | 0.00 | — | 0.00 | May 30, 2006 | Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands. | |||
| CVE-2006-1247 | 0.00 | — | 0.00 | Apr 19, 2006 | rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |||
| CVE-2006-1246 | 0.00 | — | 0.00 | Mar 17, 2006 | Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability. |
- CVE-2007-0978Feb 16, 2007risk 0.00cvss —epss 0.00
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
- CVE-2007-0670Feb 3, 2007risk 0.00cvss —epss 0.00
Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.
- CVE-2007-0618Jan 31, 2007risk 0.00cvss —epss 0.02
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
- CVE-2007-0392Jan 19, 2007risk 0.00cvss —epss 0.00
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
- CVE-2006-6915Dec 31, 2006risk 0.00cvss —epss 0.01
ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
- CVE-2006-6914Dec 31, 2006risk 0.00cvss —epss 0.02
Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.
- CVE-2006-5008Sep 27, 2006risk 0.00cvss —epss 0.03
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.
- CVE-2006-5003Sep 27, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
- CVE-2006-5004Sep 27, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
- CVE-2006-5010Sep 27, 2006risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
- CVE-2006-5006Sep 27, 2006risk 0.00cvss —epss 0.00
Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.
- CVE-2006-5005Sep 27, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.
- CVE-2006-5007Sep 27, 2006risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
- CVE-2006-5011Sep 27, 2006risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".
- CVE-2006-5009Sep 27, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.
- CVE-2006-4522Sep 1, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
- CVE-2006-4416Aug 28, 2006risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.
- CVE-2006-2647May 30, 2006risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
- CVE-2006-1247Apr 19, 2006risk 0.00cvss —epss 0.00
rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2006-1246Mar 17, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.
Page 14 of 21