Vulnerabilities
Vulnerable Software
Ibm:  >> Aix  >> 4.2.1  Security Vulnerabilities
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
CVSS Score
7.2
EPSS Score
0.001
Published
1999-09-23
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVSS Score
7.5
EPSS Score
0.073
Published
1999-09-13
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVSS Score
7.2
EPSS Score
0.004
Published
1999-09-13
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
CVSS Score
4.6
EPSS Score
0.001
Published
1999-05-06
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
CVSS Score
10.0
EPSS Score
0.075
Published
1999-02-17
Vacation program allows command execution by remote users through a sendmail command.
CVSS Score
7.5
EPSS Score
0.029
Published
1998-11-16
Buffer overflows in Sun libnsl allow root access.
CVSS Score
7.2
EPSS Score
0.001
Published
1998-05-14
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CVSS Score
10.0
EPSS Score
0.805
Published
1998-04-08
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
CVSS Score
10.0
EPSS Score
0.903
Published
1998-04-01
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
CVSS Score
1.2
EPSS Score
0.001
Published
1998-02-25


Contact Us

Shodan ® - All rights reserved