Vulnerabilities > IBM > AIX > 6.1.2

DATE CVE VULNERABILITY TITLE RISK
2018-02-13 CVE-2018-1383 Unspecified vulnerability in IBM AIX
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine.
network
low complexity
ibm
critical
9.0
2009-10-15 CVE-2009-3699 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX and Vios
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
network
low complexity
ibm CWE-119
critical
10.0
2009-10-01 CVE-2009-3517 Authentication Bypass vulnerability in IBM AIX 'nfs_portmon'
nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
network
low complexity
ibm
critical
10.0
2009-10-01 CVE-2009-3516 Credentials Management vulnerability in IBM AIX
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
local
low complexity
ibm CWE-255
7.2
2009-08-10 CVE-2009-2727 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.
network
ibm CWE-119
critical
9.3
2009-02-11 CVE-2009-0536 Permissions, Privileges, and Access Controls vulnerability in IBM AIX
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
local
low complexity
ibm CWE-264
4.9
2009-01-30 CVE-2009-0370 Unspecified vulnerability in IBM AIX
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
local
low complexity
ibm
7.2
2008-12-09 CVE-2008-5387 Buffer Errors vulnerability in IBM AIX 6.1/6.1.1/6.1.2
Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.
local
high complexity
ibm CWE-119
6.2
2008-12-09 CVE-2008-5386 Buffer Errors vulnerability in IBM AIX 6.1/6.1.1/6.1.2
Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.
local
ibm CWE-119
6.9
2008-12-09 CVE-2008-5385 Permissions, Privileges, and Access Controls vulnerability in IBM AIX 6.1/6.1.1/6.1.2
enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.
local
ibm CWE-264
6.9