CVE-2016-8972
- EPSS 1.38%
- Veröffentlicht 15.02.2017 19:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
CVE-2016-6079
- EPSS 2.49%
- Veröffentlicht 15.02.2017 19:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
CVE-2017-1093
- EPSS 0.37%
- Veröffentlicht 02.02.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
CVE-2016-3053
- EPSS 2.47%
- Veröffentlicht 01.02.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
CVE-2016-6038
- EPSS 1.67%
- Veröffentlicht 26.09.2016 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
CVE-2016-0281
- EPSS 8.42%
- Veröffentlicht 08.08.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
CVE-2016-0266
- EPSS 1.44%
- Veröffentlicht 08.08.2016 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
CVE-2015-4948
- EPSS 0.36%
- Veröffentlicht 16.10.2015 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
CVE-2014-8904
- EPSS 0.96%
- Veröffentlicht 15.01.2015 22:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
CVE-2014-3566
- EPSS 100%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 28.05.2026 18:16:23
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.