Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2010-1039

Disclosure Date: May 20, 2010 (last updated October 04, 2023)
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
0
Attacker Value
Unknown

CVE-2009-3699

Disclosure Date: October 15, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
0
Attacker Value
Unknown

CVE-2006-1247

Disclosure Date: April 19, 2006 (last updated October 04, 2023)
rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown

CVE-2005-4272

Disclosure Date: December 15, 2005 (last updated October 04, 2023)
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
0
Attacker Value
Unknown

CVE-2005-3396

Disclosure Date: November 01, 2005 (last updated October 04, 2023)
Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
0
Attacker Value
Unknown

CVE-2005-2233

Disclosure Date: July 12, 2005 (last updated October 04, 2023)
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.
0
Attacker Value
Unknown

CVE-2005-2235

Disclosure Date: July 12, 2005 (last updated October 04, 2023)
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
0
Attacker Value
Unknown

CVE-2004-1054

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
0
Attacker Value
Unknown

CVE-2004-1028

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.
0
Attacker Value
Unknown

CVE-2004-2697

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
0