[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-1999-1117
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

CVE-1999-0064
Buffer overflow in AIX lquerylv program gives root access to local users.

CVE-1999-1079
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

CVE-1999-0023
Local user gains root privileges via buffer overflow in rdist, via lookup() function.

CVE-1999-0022
Local user gains root privileges via buffer overflow in rdist, via expstr() function.

CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.

CVE-1999-0101
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.

CVE-1999-0345
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

CVE-1999-0116
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

CVE-1999-1208
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.

CVE-1999-0118
AIX infod allows local users to gain root access through an X display.

CVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

CVE-1999-0111
RIP v1 is susceptible to spoofing.

CVE-1999-0112
Buffer overflow in AIX dtterm program for the CDE.

CVE-1999-0038
Buffer overflow in xlock program allows local users to execute commands as root.

CVE-1999-0072
Buffer overflow in AIX xdat gives root access to local users.

CVE-1999-0128
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

CVE-1999-0208
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

CVE-1999-0087
Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.

CVE-1999-0086
AIX routed allows remote users to modify sensitive files.

CVE-1999-0122
Buffer overflow in AIX lchangelv gives root access.

CVE-1999-0003
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

CVE-1999-0048
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

CVE-1999-0041
Buffer overflow in NLS (Natural Language Service).

CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

CVE-1999-0018
Buffer overflow in statd allows root privileges.

CVE-1999-0017
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

CVE-1999-0019
Delete or create a file via rpc.statd, due to invalid information.

CVE-1999-0010
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

CVE-1999-0097
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

CVE-1999-0011
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

CVE-1999-0099
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.

CVE-1999-0014
Unauthorized privileged access or denial of service via dtappgather program in CDE.

CVE-1999-0090
Buffer overflow in AIX rcp command allows local users to obtain root access.

CVE-1999-0091
Buffer overflow in AIX writesrv command allows local users to obtain root access.

CVE-1999-0094
AIX piodmgrsu command allows local users to gain additional group privileges.

CVE-1999-0093
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.

CVE-1999-1405
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a ...

CVE-1999-1408
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVE-1999-1486
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.

CVE-1999-1487
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.

CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

CVE-2000-0441
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.

CVE-2010-1039
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request cont ...

CVE-2010-3187
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

CVE-1999-0046
Buffer overflow of rlogin program using TERM environmental variable.

*CPE
cpe:/o:ibm:aix:4.1
OVAL    2
oval:org.secpod.oval:def:1100031
oval:org.secpod.oval:def:1100043

© SecPod Technologies