VYPR

Aix

by IBM

CVEs (554)

  • CVE-2012-4833Oct 1, 2012
    risk 0.00cvss —epss 0.00

    fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.

  • CVE-2012-0723Jul 30, 2012
    risk 0.00cvss —epss 0.00

    The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.

  • CVE-2012-2200Jun 27, 2012
    risk 0.00cvss —epss 0.00

    The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.

  • CVE-2012-2192Jun 20, 2012
    risk 0.00cvss —epss 0.00

    The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.

  • CVE-2012-0745May 4, 2012
    risk 0.00cvss —epss 0.00

    The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.

  • CVE-2011-1385Mar 2, 2012
    risk 0.00cvss —epss 0.04

    IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.

  • CVE-2012-0194Feb 6, 2012
    risk 0.00cvss —epss 0.03

    The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.

  • CVE-2011-1384Jan 4, 2012
    risk 0.00cvss —epss 0.00

    The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an…

  • CVE-2011-1375Nov 11, 2011
    risk 0.00cvss —epss 0.00

    IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.

  • CVE-2011-3982Oct 5, 2011
    risk 0.00cvss —epss 0.00

    The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer…

  • CVE-2011-1561Apr 5, 2011
    risk 0.00cvss —epss 0.02

    The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.

  • CVE-2011-0637Jan 25, 2011
    risk 0.00cvss —epss 0.00

    The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.

  • CVE-2010-3406Sep 16, 2010
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.

  • CVE-2010-3405Sep 16, 2010
    risk 0.00cvss —epss 0.00

    Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.

  • CVE-2010-1124Mar 26, 2010
    risk 0.00cvss —epss 0.01

    bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM…

  • CVE-2010-0961Mar 10, 2010
    risk 0.00cvss —epss 0.00

    Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

  • CVE-2010-0960Mar 10, 2010
    risk 0.00cvss —epss 0.00

    Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

  • CVE-2010-0922Mar 3, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors. NOTE: some of these details are obtained from third party information. NOTE: there may be no attacker role, and…

  • CVE-2009-4362Dec 21, 2009
    risk 0.00cvss —epss 0.00

    Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments. NOTE: some of these details are obtained from third party information.

  • CVE-2009-4361Dec 21, 2009
    risk 0.00cvss —epss 0.00

    Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument. NOTE: some of these details are obtained from third party information.

Page 17 of 28