Vulnerabilities > IBM > AIX > 4.2.1

DATE CVE VULNERABILITY TITLE RISK
2000-05-24 CVE-2000-0441 Unspecified vulnerability in IBM AIX
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
network
low complexity
ibm
5.0
1999-09-23 CVE-1999-1013 Unspecified vulnerability in IBM AIX 4.1.5/4.2.1
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
local
low complexity
ibm
7.2
1999-09-13 CVE-1999-0691 Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
local
low complexity
cde digital ibm sun
7.2
1999-09-13 CVE-1999-0687 The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
network
low complexity
cde digital ibm sun
7.5
1999-05-06 CVE-1999-1079 Unspecified vulnerability in IBM AIX
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
local
low complexity
ibm
4.6
1999-02-17 CVE-1999-1405 Unspecified vulnerability in IBM AIX
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
network
low complexity
ibm
critical
10.0
1998-05-14 CVE-1999-0055 Buffer overflows in Sun libnsl allow root access.
local
low complexity
ibm sun
7.2
1998-04-08 CVE-1999-0009 Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
network
low complexity
data-general isc sgi bsdi caldera ibm nec netbsd redhat sco sun
critical
10.0
1998-04-01 CVE-1999-0003 Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
network
low complexity
tritreal sgi hp ibm sun
critical
10.0
1998-02-25 CVE-1999-1486 Unspecified vulnerability in IBM AIX
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
ibm
1.2