VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
Published 2002-06-25 · Modified
10.08 PoCEPSS 0.947
CVE-2003-0694
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Published 2003-09-18 · Modified
10.0EPSS 0.662
CVE-2009-3699
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
Published 2009-10-15 · Modified
10.01 PoCEPSS 0.623
CVE-1999-0046
Buffer overflow of rlogin program using TERM environmental variable.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.519
CVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.387
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.290
CVE-1999-0003
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.246
CVE-2002-0679
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
Published 2003-04-02 · Modified
10.0EPSS 0.233
CVE-2010-1039
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
Published 2010-05-20 · Modified
10.01 PoCEPSS 0.202
CVE-2010-3187
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
Published 2010-08-30 · Modified
10.02 PoCEPSS 0.200
CVE-1999-0113
Some implementations of rlogin allow root access if given a -froot parameter.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.172
CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Published 2001-01-22 · Modified
10.011 PoCEPSS 0.156
CVE-1999-0208
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.129
CVE-1999-0042
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.127
CVE-2004-0368
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
Published 2004-03-25 · Modified
10.0EPSS 0.106
CVE-1999-0018
Buffer overflow in statd allows root privileges.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.105
CVE-2005-4272
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
Published 2005-12-15 · Modified
10.0EPSS 0.090
CVE-1999-0101
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
Published 2000-01-18 · Modified
10.01 PoCEPSS 0.078
CVE-2007-1917
Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2007-1916
Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2002-1621
Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.
Published 2005-03-26 · Modified
10.0EPSS 0.066
CVE-2002-0747
Buffer overflow in lsmcode in AIX 4.3.3.
Published 2002-07-26 · Modified
10.01 PoCEPSS 0.060
CVE-2001-1080
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.060
CVE-1999-0011
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Published 1999-09-29 · Modified
10.0EPSS 0.055
CVE-2010-4773
Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service before 05-10 -/D 2010.11.15; and uCosminexus EUR Form Service before 07-60 -/D 2010.11.15 on Windows, before 05-10 -/D 2010.11.15 and 07-50 -/D 2010.11.15 on Linux, and before 07-50 -/C 2010.11.15 on AIX; allows remote attackers to execute arbitrary code via unknown attack vectors.
Published 2011-03-23 · Modified
10.0EPSS 0.053
CVE-2001-1440
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
Published 2005-04-21 · Modified
10.0EPSS 0.050
CVE-2001-0671
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
Published 2001-11-22 · Modified
10.0EPSS 0.048
CVE-2009-3517
nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
Published 2009-10-01 · Modified
10.0EPSS 0.044
CVE-1999-1119
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
Published 2002-03-09 · Modified
10.0EPSS 0.042
CVE-2002-1468
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
Published 2004-09-01 · Modified
10.01 PoCEPSS 0.041
CVE-1999-0097
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Published 1999-09-29 · Modified
10.0EPSS 0.040
CVE-1999-0088
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
Published 2000-02-04 · Modified
10.0EPSS 0.040
CVE-2006-5008
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.
Published 2006-09-27 · Modified
10.0EPSS 0.035
CVE-1999-1405
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
Published 2001-09-12 · Modified
10.01 PoCEPSS 0.033
CVE-1999-0745
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
Published 2000-01-04 · Modified
10.01 PoCEPSS 0.033
CVE-1999-0099
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Published 1999-09-29 · Modified
10.0EPSS 0.033
CVE-1999-0048
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
Published 1999-09-29 · Modified
10.0EPSS 0.031
CVE-1999-0789
Buffer overflow in AIX ftpd in the libc library.
Published 2000-03-22 · Modified
10.01 PoCEPSS 0.031
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published 2019-11-14 · Modified
10.0EPSS 0.030
CVE-2003-0170
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
Published 2004-03-10 · Modified
10.0EPSS 0.028
1 / 25Next →