VendorsIBMaix4.3.2
Vulnerabilities

IBM AIX 4.3.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
Published 2002-06-25 · Modified
10.08 PoCEPSS 0.947
CVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.387
CVE-2010-1039
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
Published 2010-05-20 · Modified
10.01 PoCEPSS 0.202
CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Published 2001-01-22 · Modified
10.011 PoCEPSS 0.156
CVE-2002-1621
Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.
Published 2005-03-26 · Modified
10.0EPSS 0.066
CVE-1999-0789
Buffer overflow in AIX ftpd in the libc library.
Published 2000-03-22 · Modified
10.01 PoCEPSS 0.031
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-0903
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
Published 2000-04-18 · Modified
7.5EPSS 0.015
CVE-2000-1120
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
Published 2001-01-22 · Modified
7.21 PoCEPSS 0.010
CVE-2000-1121
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.010
CVE-2000-1124
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2000-1123
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-2000-1122
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-2000-0466
AIX cdmount allows local users to gain root privileges via shell metacharacters.
Published 2000-10-13 · Modified
7.2EPSS 0.004
CVE-2003-0257
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
Published 2004-03-16 · Modified
7.2EPSS 0.004
CVE-2000-0249
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
Published 2000-07-12 · Modified
7.2EPSS 0.003
CVE-2002-1619
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
Published 2005-03-26 · Modified
5.0EPSS 0.022
CVE-2000-0441
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
Published 2000-07-12 · Modified
5.0EPSS 0.009
CVE-2000-1119
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
Published 2001-05-07 · Modified
4.61 PoCEPSS 0.010
CVE-1999-1079
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-2000-0873
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
Published 2001-01-22 · Modified
2.11 PoCEPSS 0.006
CVE-2000-0080
AIX techlibss allows local users to overwrite files via a symlink attack.
Published 2001-01-22 · Modified
2.1EPSS 0.003