| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood. |
| The rwho/rwhod service is running, which exposes machine status and user information. |
| AIX passwd allows local users to gain root access. |
| AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. |
| Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. |
| clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges. |
| Denial of service in BIND named via malformed SIG records. |
| Buffer overflow in lsmcode in AIX 4.3.3. |
| Buffer overflow in AIX xdat gives root access to local users. |
| The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. |
| Buffer overflow in AIX writesrv command allows local users to obtain root access. |
| Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. |
| Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. |
| Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. |
| Buffer overflow in uucp in AIX 4.3.3. |
| namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. |
| Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. |
| mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow. |
| Delete or create a file via rpc.statd, due to invalid information. |
| Buffer overflow in pioout on AIX 4.3.3. |