Vulnerabilities > IBM > AIX > 4.1

DATE CVE VULNERABILITY TITLE RISK
1999-02-17 CVE-1999-1405 Unspecified vulnerability in IBM AIX
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
network
low complexity
ibm
critical
10.0
1998-11-01 CVE-1999-0118 Unspecified vulnerability in IBM AIX
AIX infod allows local users to gain root access through an X display.
local
low complexity
ibm
7.2
1998-04-08 CVE-1999-0011 Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
network
low complexity
data-general isc ibm nec netbsd redhat sco sun
critical
10.0
1998-04-08 CVE-1999-0010 Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
network
low complexity
data-general isc ibm nec netbsd redhat sco sun
5.0
1998-04-08 CVE-1999-0009 Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
network
low complexity
data-general isc sgi bsdi caldera ibm nec netbsd redhat sco sun
critical
10.0
1998-04-01 CVE-1999-0003 Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
network
low complexity
tritreal sgi hp ibm sun
critical
10.0
1998-02-25 CVE-1999-1486 Unspecified vulnerability in IBM AIX
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
ibm
1.2
1998-02-01 CVE-1999-0087 Unspecified vulnerability in IBM AIX 4.1/4.2/4.3
Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
network
low complexity
ibm
5.0
1998-01-21 CVE-1999-1487 Unspecified vulnerability in IBM AIX
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
local
low complexity
ibm
7.2
1998-01-21 CVE-1999-0014 Unauthorized privileged access or denial of service via dtappgather program in CDE.
local
low complexity
cde hp ibm
7.2