Vulnerabilities
Vulnerable Software
Ibm:  >> Aix  >> 5.3  Security Vulnerabilities
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-07-12
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
CVSS Score
7.2
EPSS Score
0.006
Published
2005-07-12
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-07-12
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-07-12
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-05-02
Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.
CVSS Score
7.2
EPSS Score
0.004
Published
2005-05-02
Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
CVSS Score
7.2
EPSS Score
0.004
Published
2005-05-02
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-05-02
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-02-10
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
CVSS Score
2.1
EPSS Score
0.004
Published
2005-02-07


Contact Us

Shodan ® - All rights reserved