CVE-2004-1330
- EPSS 0.33%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
CVE-2004-2312
- EPSS 0.32%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
- EPSS 1.01%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
CVE-2004-2697
- EPSS 0.7%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
CVE-2004-1329
- EPSS 0.58%
- Veröffentlicht 20.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point...
- EPSS 1.09%
- Veröffentlicht 23.11.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
CVE-2004-0828
- EPSS 0.08%
- Veröffentlicht 03.11.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
CVE-2004-0544
- EPSS 0.7%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
CVE-2004-0545
- EPSS 0.05%
- Veröffentlicht 06.08.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.
- EPSS 59.18%
- Veröffentlicht 04.05.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.