Show filters
80 Total Results
Displaying 61-70 of 80
Sort by:
Attacker Value
Unknown

CVE-2013-3005

Disclosure Date: July 06, 2013 (last updated October 05, 2023)
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3035

Disclosure Date: June 21, 2013 (last updated October 05, 2023)
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
0
Attacker Value
Unknown

CVE-2013-0142

Disclosure Date: June 07, 2013 (last updated October 05, 2023)
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-0143

Disclosure Date: June 07, 2013 (last updated October 05, 2023)
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.
0
Attacker Value
Unknown

CVE-2013-0144

Disclosure Date: June 07, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.
0
Attacker Value
Unknown

CVE-2012-4845

Disclosure Date: October 20, 2012 (last updated October 05, 2023)
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
0
Attacker Value
Unknown

CVE-2012-4833

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
0
Attacker Value
Unknown

CVE-2012-4817

Disclosure Date: September 14, 2012 (last updated October 05, 2023)
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0723

Disclosure Date: July 30, 2012 (last updated October 04, 2023)
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
0
Attacker Value
Unknown

CVE-2012-2200

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
0