VYPR

Aix

by IBM

CVEs (402)

  • CVE-2004-0545Aug 6, 2004
    risk 0.00cvss epss 0.00

    LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2003-0257Apr 15, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

  • CVE-2003-0170Mar 29, 2004
    risk 0.00cvss epss 0.03

    Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

  • CVE-2003-1018Mar 29, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

  • CVE-2003-0119Feb 3, 2004
    risk 0.00cvss epss 0.02

    The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.

  • CVE-2003-0696Jan 20, 2004
    risk 0.00cvss epss 0.01

    The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).

  • CVE-2003-0954Dec 31, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.

  • CVE-2003-0914Dec 15, 2003
    risk 0.00cvss epss 0.03

    ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

  • CVE-2003-0697Oct 6, 2003
    risk 0.00cvss epss 0.00

    Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

  • CVE-2003-0784Oct 6, 2003
    risk 0.00cvss epss 0.02

    Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

  • CVE-2003-0285Jun 16, 2003
    risk 0.00cvss epss 0.05

    IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam…

  • CVE-2002-1550Mar 31, 2003
    risk 0.00cvss epss 0.00

    dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2002-1548Mar 31, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."

  • CVE-2002-1551Mar 31, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.

  • CVE-2003-0064Mar 3, 2003
    risk 0.00cvss epss 0.03

    The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker…

  • CVE-2002-1689Dec 31, 2002
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

  • CVE-2002-1622Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."

  • CVE-2002-1686Dec 31, 2002
    risk 0.00cvss epss 0.01

    Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

  • CVE-2002-1690Dec 31, 2002
    risk 0.00cvss epss 0.01

    Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

  • CVE-2002-1687Dec 31, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.

Page 16 of 21