VYPR

Aix

by IBM

CVEs (554)

  • CVE-1999-0116Sep 19, 1996
    risk 0.03cvss —epss 0.06

    Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

  • CVE-1999-0023Jul 24, 1996
    risk 0.03cvss —epss 0.01

    Local user gains root privileges via buffer overflow in rdist, via lookup() function.

  • CVE-2002-0679Sep 5, 2002
    risk 0.02cvss —epss 0.23

    Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

  • CVE-2012-4817Sep 14, 2012
    risk 0.01cvss —epss 0.08

    The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2005-4272Dec 15, 2005
    risk 0.01cvss —epss 0.09

    Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.

  • CVE-2004-0368May 4, 2004
    risk 0.01cvss —epss 0.11

    Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

  • CVE-2003-0028Mar 25, 2003
    risk 0.01cvss —epss 0.15

    Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in…

  • CVE-2002-0678Jul 23, 2002
    risk 0.01cvss —epss 0.09

    CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

  • CVE-2002-0677Jul 23, 2002
    risk 0.01cvss —epss 0.07

    CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

  • CVE-2002-1621Apr 22, 2002
    risk 0.01cvss —epss 0.07

    Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

  • CVE-1999-0057Nov 16, 1998
    risk 0.01cvss —epss 0.08

    Vacation program allows command execution by remote users through a sendmail command.

  • CVE-1999-0627Mar 1, 1992
    risk 0.01cvss —epss 0.07

    The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.

  • CVE-2015-4948Oct 16, 2015
    risk 0.00cvss —epss 0.00

    netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

  • CVE-2014-3074Jul 2, 2014
    risk 0.00cvss —epss 0.01

    The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.

  • CVE-2014-0930May 8, 2014
    risk 0.00cvss —epss 0.00

    The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.

  • CVE-2014-0899Mar 11, 2014
    risk 0.00cvss —epss 0.02

    ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.

  • CVE-2013-5419Oct 4, 2013
    risk 0.00cvss —epss 0.00

    Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.

  • CVE-2013-3005Jul 6, 2013
    risk 0.00cvss —epss 0.03

    The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.

  • CVE-2013-3035Jun 21, 2013
    risk 0.00cvss —epss 0.04

    The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

  • CVE-2012-4845Oct 20, 2012
    risk 0.00cvss —epss 0.02

    The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

Page 16 of 28