National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:ibm:aix:4.2
There are 58 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2011-1384

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

Published: January 03, 2012; 10:55:04 PM -05:00
V2: 4.0 MEDIUM
CVE-2010-3187

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

Published: August 30, 2010; 04:00:04 PM -04:00
V2: 10.0 HIGH
CVE-2010-1039

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

Published: May 20, 2010; 01:30:01 PM -04:00
V2: 10.0 HIGH
CVE-2003-0285

IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.

Published: June 16, 2003; 12:00:00 AM -04:00
V2: 5.0 MEDIUM
CVE-2000-1119

Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.

Published: January 09, 2001; 12:00:00 AM -05:00
V2: 4.6 MEDIUM
CVE-2000-1120

Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.

Published: January 09, 2001; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-2000-1121

Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.

Published: January 09, 2001; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-2000-1122

Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.

Published: January 09, 2001; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-2000-1222

AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.

Published: December 10, 2000; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-2000-0844

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Published: November 14, 2000; 12:00:00 AM -05:00
V2: 10.0 HIGH
CVE-2000-0873

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

Published: November 14, 2000; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-2000-0441

Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.

Published: May 24, 2000; 12:00:00 AM -04:00
V2: 5.0 MEDIUM
CVE-1999-1117

lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-0687

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

Published: September 13, 1999; 12:00:00 AM -04:00
V2: 7.5 HIGH
CVE-1999-0691

Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

Published: September 13, 1999; 12:00:00 AM -04:00
V2: 7.2 HIGH
CVE-1999-0694

Denial of service in AIX ptrace system call allows local users to crash the system.

Published: August 11, 1999; 12:00:00 AM -04:00
V2: 2.1 LOW
CVE-1999-1079

Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

Published: May 06, 1999; 12:00:00 AM -04:00
V2: 4.6 MEDIUM
CVE-1999-1405

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

Published: February 17, 1999; 12:00:00 AM -05:00
V2: 10.0 HIGH
CVE-1999-0118

AIX infod allows local users to gain root access through an X display.

Published: November 01, 1998; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-1999-0055

Buffer overflows in Sun libnsl allow root access.

Published: May 14, 1998; 12:00:00 AM -04:00
V2: 7.2 HIGH