CVE-2016-0266
- EPSS 0.7%
- Published 08.08.2016 01:59:00
- Last modified 12.04.2025 10:46:40
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CVE-2015-4948
- EPSS 0.05%
- Published 16.10.2015 01:59:02
- Last modified 12.04.2025 10:46:40
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
CVE-2014-8904
- EPSS 0.56%
- Published 15.01.2015 22:59:03
- Last modified 12.04.2025 10:46:40
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
CVE-2014-3566
- EPSS 94.02%
- Published 15.10.2014 00:55:02
- Last modified 12.04.2025 10:46:40
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVE-2014-3074
- EPSS 0.08%
- Published 02.07.2014 10:35:25
- Last modified 12.04.2025 10:46:40
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a se...
CVE-2014-3977
- EPSS 0.16%
- Published 08.06.2014 23:55:04
- Last modified 12.04.2025 10:46:40
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
CVE-2014-0930
- EPSS 0.11%
- Published 08.05.2014 10:55:03
- Last modified 12.04.2025 10:46:40
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
CVE-2014-0899
- EPSS 0.3%
- Published 11.03.2014 13:01:09
- Last modified 12.04.2025 10:46:40
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
CVE-2013-5419
- EPSS 0.05%
- Published 04.10.2013 10:44:07
- Last modified 11.04.2025 00:51:21
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
CVE-2013-4011
- EPSS 8.47%
- Published 18.07.2013 16:51:55
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.