Aix
by IBM
CVEs (554)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-1222 | 0.00 | — | 0.00 | Dec 10, 2000 | AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program. | |||
| CVE-2000-0466 | 0.00 | — | 0.00 | Jun 20, 2000 | AIX cdmount allows local users to gain root privileges via shell metacharacters. | |||
| CVE-2000-0441 | 0.00 | — | 0.01 | May 24, 2000 | Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems. | |||
| CVE-2000-0249 | 0.00 | — | 0.00 | Apr 26, 2000 | The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program. | |||
| CVE-2000-1216 | 0.00 | — | 0.00 | Jan 27, 2000 | Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine. | |||
| CVE-2000-0080 | 0.00 | — | 0.00 | Jan 10, 2000 | AIX techlibss allows local users to overwrite files via a symlink attack. | |||
| CVE-1999-1589 | 0.00 | — | 0.00 | Dec 31, 1999 | Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors. | |||
| CVE-1999-0835 | 0.00 | — | 0.01 | Nov 10, 1999 | Denial of service in BIND named via malformed SIG records. | |||
| CVE-1999-0851 | 0.00 | — | 0.00 | Nov 10, 1999 | Denial of service in BIND named via naptr. | |||
| CVE-1999-0903 | 0.00 | — | 0.02 | Oct 26, 1999 | genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767. | |||
| CVE-1999-1583 | 0.00 | — | 0.01 | Sep 30, 1999 | Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument. | |||
| CVE-1999-1013 | 0.00 | — | 0.00 | Sep 23, 1999 | named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file. | |||
| CVE-1999-0687 | 0.00 | — | 0.02 | Sep 13, 1999 | The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. | |||
| CVE-1999-0694 | 0.00 | — | 0.00 | Aug 11, 1999 | Denial of service in AIX ptrace system call allows local users to crash the system. | |||
| CVE-1999-1079 | 0.00 | — | 0.00 | May 6, 1999 | Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. | |||
| CVE-1999-0088 | 0.00 | — | 0.04 | Oct 26, 1998 | IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. | |||
| CVE-1999-1574 | 0.00 | — | 0.03 | Jul 6, 1998 | Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings." | |||
| CVE-1999-1480 | 0.00 | — | 0.00 | Jun 11, 1998 | (1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack. | |||
| CVE-1999-0055 | 0.00 | — | 0.00 | May 14, 1998 | Buffer overflows in Sun libnsl allow root access. | |||
| CVE-1999-0010 | 0.00 | — | 0.02 | Apr 8, 1998 | Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. |
- CVE-2000-1222Dec 10, 2000risk 0.00cvss —epss 0.00
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
- CVE-2000-0466Jun 20, 2000risk 0.00cvss —epss 0.00
AIX cdmount allows local users to gain root privileges via shell metacharacters.
- CVE-2000-0441May 24, 2000risk 0.00cvss —epss 0.01
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
- CVE-2000-0249Apr 26, 2000risk 0.00cvss —epss 0.00
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
- CVE-2000-1216Jan 27, 2000risk 0.00cvss —epss 0.00
Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.
- CVE-2000-0080Jan 10, 2000risk 0.00cvss —epss 0.00
AIX techlibss allows local users to overwrite files via a symlink attack.
- CVE-1999-1589Dec 31, 1999risk 0.00cvss —epss 0.00
Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
- CVE-1999-0835Nov 10, 1999risk 0.00cvss —epss 0.01
Denial of service in BIND named via malformed SIG records.
- CVE-1999-0851Nov 10, 1999risk 0.00cvss —epss 0.00
Denial of service in BIND named via naptr.
- CVE-1999-0903Oct 26, 1999risk 0.00cvss —epss 0.02
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
- CVE-1999-1583Sep 30, 1999risk 0.00cvss —epss 0.01
Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
- CVE-1999-1013Sep 23, 1999risk 0.00cvss —epss 0.00
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
- CVE-1999-0687Sep 13, 1999risk 0.00cvss —epss 0.02
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
- CVE-1999-0694Aug 11, 1999risk 0.00cvss —epss 0.00
Denial of service in AIX ptrace system call allows local users to crash the system.
- CVE-1999-1079May 6, 1999risk 0.00cvss —epss 0.00
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
- CVE-1999-0088Oct 26, 1998risk 0.00cvss —epss 0.04
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
- CVE-1999-1574Jul 6, 1998risk 0.00cvss —epss 0.03
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
- CVE-1999-1480Jun 11, 1998risk 0.00cvss —epss 0.00
(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.
- CVE-1999-0055May 14, 1998risk 0.00cvss —epss 0.00
Buffer overflows in Sun libnsl allow root access.
- CVE-1999-0010Apr 8, 1998risk 0.00cvss —epss 0.02
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Page 26 of 28