Aix
by IBM
CVEs (409)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-1551 | 0.00 | — | 0.00 | Mar 31, 2003 | Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code. | |||
| CVE-2003-0064 | 0.00 | — | 0.03 | Mar 3, 2003 | The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker… | |||
| CVE-2002-1687 | 0.00 | — | 0.00 | Dec 31, 2002 | Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable. | |||
| CVE-2002-1686 | 0.00 | — | 0.01 | Dec 31, 2002 | Buffer overflow in lscfg of unknown versions of AIX has unknown impact. | |||
| CVE-2002-1690 | 0.00 | — | 0.01 | Dec 31, 2002 | Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225. | |||
| CVE-2002-1689 | 0.00 | — | 0.02 | Dec 31, 2002 | Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. | |||
| CVE-2002-1622 | 0.00 | — | 0.03 | Dec 31, 2002 | Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type." | |||
| CVE-2002-1201 | 0.00 | — | 0.02 | Oct 28, 2002 | IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers. | |||
| CVE-2002-1041 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. | |||
| CVE-2002-1040 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. | |||
| CVE-2002-0790 | 0.00 | — | 0.00 | Aug 12, 2002 | clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges. | |||
| CVE-2002-0744 | 0.00 | — | 0.01 | Aug 12, 2002 | namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. | |||
| CVE-2002-0743 | 0.00 | — | 0.01 | Aug 12, 2002 | mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow. | |||
| CVE-2002-0745 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in uucp in AIX 4.3.3. | |||
| CVE-2002-0742 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in pioout on AIX 4.3.3. | |||
| CVE-2002-0746 | 0.00 | — | 0.02 | Aug 12, 2002 | Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. | |||
| CVE-2002-1619 | 0.00 | — | 0.02 | Mar 8, 2002 | Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump). | |||
| CVE-2001-1079 | 0.00 | — | 0.00 | Feb 13, 2002 | create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service. | |||
| CVE-2002-1594 | 0.00 | — | 0.01 | Jan 2, 2002 | Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument. | |||
| CVE-2001-1557 | 0.00 | — | 0.01 | Dec 31, 2001 | Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges. |
- CVE-2002-1551Mar 31, 2003risk 0.00cvss —epss 0.00
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
- CVE-2003-0064Mar 3, 2003risk 0.00cvss —epss 0.03
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker…
- CVE-2002-1687Dec 31, 2002risk 0.00cvss —epss 0.00
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
- CVE-2002-1686Dec 31, 2002risk 0.00cvss —epss 0.01
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
- CVE-2002-1690Dec 31, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
- CVE-2002-1689Dec 31, 2002risk 0.00cvss —epss 0.02
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
- CVE-2002-1622Dec 31, 2002risk 0.00cvss —epss 0.03
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
- CVE-2002-1201Oct 28, 2002risk 0.00cvss —epss 0.02
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
- CVE-2002-1041Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
- CVE-2002-1040Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
- CVE-2002-0790Aug 12, 2002risk 0.00cvss —epss 0.00
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
- CVE-2002-0744Aug 12, 2002risk 0.00cvss —epss 0.01
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
- CVE-2002-0743Aug 12, 2002risk 0.00cvss —epss 0.01
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
- CVE-2002-0745Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in uucp in AIX 4.3.3.
- CVE-2002-0742Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in pioout on AIX 4.3.3.
- CVE-2002-0746Aug 12, 2002risk 0.00cvss —epss 0.02
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
- CVE-2002-1619Mar 8, 2002risk 0.00cvss —epss 0.02
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
- CVE-2001-1079Feb 13, 2002risk 0.00cvss —epss 0.00
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
- CVE-2002-1594Jan 2, 2002risk 0.00cvss —epss 0.01
Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument.
- CVE-2001-1557Dec 31, 2001risk 0.00cvss —epss 0.01
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
Page 17 of 21