CVE-2014-3074
- EPSS 0.58%
- Veröffentlicht 02.07.2014 10:35:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a se...
CVE-2014-3977
- EPSS 0.87%
- Veröffentlicht 08.06.2014 23:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
CVE-2014-0930
- EPSS 0.47%
- Veröffentlicht 08.05.2014 10:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
CVE-2014-0899
- EPSS 1.87%
- Veröffentlicht 11.03.2014 13:01:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
CVE-2013-5419
- EPSS 0.37%
- Veröffentlicht 04.10.2013 10:44:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
CVE-2013-4011
- EPSS 2.85%
- Veröffentlicht 18.07.2013 16:51:55
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
CVE-2013-3005
- EPSS 2.96%
- Veröffentlicht 06.07.2013 13:57:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
CVE-2013-3035
- EPSS 3.63%
- Veröffentlicht 21.06.2013 14:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
CVE-2012-4845
- EPSS 1.62%
- Veröffentlicht 20.10.2012 10:41:27
- Zuletzt bearbeitet 16.06.2026 23:45:46
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executa...
CVE-2012-4833
- EPSS 0.39%
- Veröffentlicht 01.10.2012 18:55:01
- Zuletzt bearbeitet 16.06.2026 23:45:45
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.