Vulnerabilities > IBM > AIX > 6.1

DATE CVE VULNERABILITY TITLE RISK
2015-11-08 CVE-2015-5005 Permissions, Privileges, and Access Controls vulnerability in IBM Powerha System Mirror
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.
network
ibm CWE-264
8.5
2015-10-16 CVE-2015-4948 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
local
ibm CWE-264
6.9
2015-01-15 CVE-2014-8904 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
local
low complexity
ibm CWE-264
7.2
2014-10-15 CVE-2014-3566 Cryptographic Issues vulnerability in multiple products
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
3.4
2014-07-02 CVE-2014-3074 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
local
low complexity
ibm CWE-264
7.2
2014-06-08 CVE-2014-3977 Link Following vulnerability in IBM AIX and Vios
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
ibm CWE-59
6.9
2014-05-08 CVE-2014-0930 Unspecified vulnerability in IBM AIX and Vios
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
local
ibm
4.7
2013-10-04 CVE-2013-5419 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 6.1/7.1
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
local
ibm CWE-119
6.9
2013-07-18 CVE-2013-4011 Local Privilege Escalation vulnerability in IBM AIX
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
local
low complexity
ibm
7.2
2013-07-06 CVE-2013-3005 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
network
ibm CWE-264
8.5