Aix
by IBM
CVEs (554)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0784 | 0.00 | — | 0.02 | Oct 6, 2003 | Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers. | |||
| CVE-2003-0697 | 0.00 | — | 0.00 | Oct 6, 2003 | Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges. | |||
| CVE-2003-0285 | 0.00 | — | 0.05 | Jun 16, 2003 | IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam… | |||
| CVE-2002-1550 | 0.00 | — | 0.00 | Mar 31, 2003 | dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |||
| CVE-2002-1548 | 0.00 | — | 0.00 | Mar 31, 2003 | Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called." | |||
| CVE-2002-1551 | 0.00 | — | 0.00 | Mar 31, 2003 | Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code. | |||
| CVE-2003-0064 | 0.00 | — | 0.03 | Mar 3, 2003 | The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker… | |||
| CVE-2002-1622 | 0.00 | — | 0.03 | Dec 31, 2002 | Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type." | |||
| CVE-2002-1687 | 0.00 | — | 0.00 | Dec 31, 2002 | Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable. | |||
| CVE-2002-1686 | 0.00 | — | 0.01 | Dec 31, 2002 | Buffer overflow in lscfg of unknown versions of AIX has unknown impact. | |||
| CVE-2002-1690 | 0.00 | — | 0.01 | Dec 31, 2002 | Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225. | |||
| CVE-2002-1689 | 0.00 | — | 0.02 | Dec 31, 2002 | Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. | |||
| CVE-2002-1201 | 0.00 | — | 0.02 | Oct 28, 2002 | IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers. | |||
| CVE-2002-1041 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. | |||
| CVE-2002-1040 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. | |||
| CVE-2002-0742 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in pioout on AIX 4.3.3. | |||
| CVE-2002-0745 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in uucp in AIX 4.3.3. | |||
| CVE-2002-0746 | 0.00 | — | 0.02 | Aug 12, 2002 | Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. | |||
| CVE-2002-0744 | 0.00 | — | 0.01 | Aug 12, 2002 | namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. | |||
| CVE-2002-0743 | 0.00 | — | 0.01 | Aug 12, 2002 | mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow. |
- CVE-2003-0784Oct 6, 2003risk 0.00cvss —epss 0.02
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
- CVE-2003-0697Oct 6, 2003risk 0.00cvss —epss 0.00
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
- CVE-2003-0285Jun 16, 2003risk 0.00cvss —epss 0.05
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam…
- CVE-2002-1550Mar 31, 2003risk 0.00cvss —epss 0.00
dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2002-1548Mar 31, 2003risk 0.00cvss —epss 0.00
Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
- CVE-2002-1551Mar 31, 2003risk 0.00cvss —epss 0.00
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
- CVE-2003-0064Mar 3, 2003risk 0.00cvss —epss 0.03
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker…
- CVE-2002-1622Dec 31, 2002risk 0.00cvss —epss 0.03
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
- CVE-2002-1687Dec 31, 2002risk 0.00cvss —epss 0.00
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
- CVE-2002-1686Dec 31, 2002risk 0.00cvss —epss 0.01
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
- CVE-2002-1690Dec 31, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
- CVE-2002-1689Dec 31, 2002risk 0.00cvss —epss 0.02
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
- CVE-2002-1201Oct 28, 2002risk 0.00cvss —epss 0.02
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
- CVE-2002-1041Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
- CVE-2002-1040Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
- CVE-2002-0742Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in pioout on AIX 4.3.3.
- CVE-2002-0745Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in uucp in AIX 4.3.3.
- CVE-2002-0746Aug 12, 2002risk 0.00cvss —epss 0.02
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
- CVE-2002-0744Aug 12, 2002risk 0.00cvss —epss 0.01
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
- CVE-2002-0743Aug 12, 2002risk 0.00cvss —epss 0.01
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
Page 24 of 28