Download
| Alert*
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. CVE-1999-0064 Buffer overflow in AIX lquerylv program gives root access to local users. CVE-1999-1079 Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. CVE-1999-0122 Buffer overflow in AIX lchangelv gives root access. CVE-1999-0022 Local user gains root privileges via buffer overflow in rdist, via expstr() function. CVE-1999-0003 Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). CVE-1999-0687 The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. CVE-1999-0097 The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). CVE-1999-0691 Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. CVE-1999-0090 Buffer overflow in AIX rcp command allows local users to obtain root access. CVE-1999-0091 Buffer overflow in AIX writesrv command allows local users to obtain root access. CVE-1999-0072 Buffer overflow in AIX xdat gives root access to local users. CVE-1999-0094 AIX piodmgrsu command allows local users to gain additional group privileges. CVE-1999-0093 AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. CVE-2000-0844 Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. CVE-1999-1405 snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a ... CVE-2000-0441 Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems. CVE-1999-1408 Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. CVE-1999-1486 sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack. CVE-1999-1487 Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system. CVE-2010-1039 Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request cont ... CVE-2010-3187 Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command. CVE-1999-0046 Buffer overflow of rlogin program using TERM environmental variable. |