Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Aix
Total 705 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1408 2 Hp, Ibm 2 Hp-ux, Aix 2024-02-28 2.1 LOW N/A
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
CVE-1999-0687 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2024-02-28 7.5 HIGH N/A
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-2004-0828 1 Ibm 1 Aix 2024-02-28 2.1 LOW N/A
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
CVE-2003-0119 1 Ibm 1 Aix 2024-02-28 7.5 HIGH N/A
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
CVE-2003-0028 10 Cray, Freebsd, Gnu and 7 more 13 Unicos, Freebsd, Glibc and 10 more 2024-02-28 7.5 HIGH N/A
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
CVE-1999-0113 1 Ibm 1 Aix 2024-02-28 10.0 HIGH N/A
Some implementations of rlogin allow root access if given a -froot parameter.
CVE-2002-0742 1 Ibm 1 Aix 2024-02-28 10.0 HIGH N/A
Buffer overflow in pioout on AIX 4.3.3.
CVE-2003-0696 1 Ibm 1 Aix 2024-02-28 5.0 MEDIUM N/A
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
CVE-1999-0099 5 Bsdi, Convex, Cray and 2 more 7 Bsd Os, Convexos, Spp-ux and 4 more 2024-02-28 10.0 HIGH N/A
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVE-2002-0790 1 Ibm 1 Aix 2024-02-28 2.1 LOW N/A
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
CVE-1999-0337 1 Ibm 1 Aix 2024-02-28 7.5 HIGH N/A
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
CVE-2000-1120 1 Ibm 1 Aix 2024-02-28 7.2 HIGH N/A
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
CVE-1999-0057 5 Eric Allman, Freebsd, Hp and 2 more 7 Vacation, Freebsd, Hp-ux and 4 more 2024-02-28 7.5 HIGH N/A
Vacation program allows command execution by remote users through a sendmail command.
CVE-1999-0089 1 Ibm 1 Aix 2024-02-28 7.2 HIGH N/A
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
CVE-1999-0903 1 Ibm 1 Aix 2024-02-28 7.5 HIGH N/A
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
CVE-2002-0678 7 Caldera, Compaq, Hp and 4 more 9 Openunix, Unixware, Tru64 and 6 more 2024-02-28 7.2 HIGH N/A
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
CVE-2002-1041 1 Ibm 1 Aix 2024-02-28 5.0 MEDIUM N/A
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
CVE-2002-0744 1 Ibm 1 Aix 2024-02-28 10.0 HIGH N/A
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
CVE-1999-0112 2 Cde, Ibm 2 Cde, Aix 2024-02-28 7.2 HIGH N/A
Buffer overflow in AIX dtterm program for the CDE.
CVE-1999-1574 1 Ibm 1 Aix 2024-02-28 7.5 HIGH N/A
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."