Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2010-1039

Disclosure Date: May 20, 2010 (last updated October 04, 2023)
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
0
Attacker Value
Unknown

CVE-2000-0844

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
0
Attacker Value
Unknown

CVE-2000-0441

Disclosure Date: May 24, 2000 (last updated February 22, 2025)
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
0
Attacker Value
Unknown

CVE-1999-1013

Disclosure Date: September 23, 1999 (last updated February 22, 2025)
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
0
Attacker Value
Unknown

CVE-1999-0687

Disclosure Date: September 13, 1999 (last updated February 22, 2025)
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
0
Attacker Value
Unknown

CVE-1999-0691

Disclosure Date: September 13, 1999 (last updated February 22, 2025)
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
0
Attacker Value
Unknown

CVE-1999-1079

Disclosure Date: May 06, 1999 (last updated February 22, 2025)
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
0
Attacker Value
Unknown

CVE-1999-1405

Disclosure Date: February 17, 1999 (last updated February 22, 2025)
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
0
Attacker Value
Unknown

CVE-1999-0009

Disclosure Date: April 08, 1998 (last updated February 22, 2025)
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
0
Attacker Value
Unknown

CVE-1999-0003

Disclosure Date: April 01, 1998 (last updated February 22, 2025)
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
0