Vulnerabilities > IBM > AIX > Low

DATE CVE VULNERABILITY TITLE RISK
2006-01-09 CVE-2006-0133 Unspecified vulnerability in IBM AIX 5.3Ml03
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a ..
local
low complexity
ibm
3.6
2005-12-15 CVE-2005-4273 Unspecified vulnerability in IBM AIX 5.3/5.3L
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
local
low complexity
ibm
2.1
2005-10-23 CVE-2005-3289 Unspecified vulnerability in IBM AIX 5.2/5.3
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
local
low complexity
ibm
2.1
2005-07-12 CVE-2005-2238 Denial-Of-Service vulnerability in IBM AIX 5.1/5.2/5.3
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
local
low complexity
ibm
2.1
2005-05-02 CVE-2005-0991 Local Insecure Temporary File Creation vulnerability in IBM AIX RC.BOOT
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
local
low complexity
ibm
2.1
2005-05-02 CVE-2005-1176 Information Disclosure vulnerability in AIX
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
local
high complexity
ibm
1.2
2005-02-10 CVE-2005-0261 Local File Disclosure vulnerability in IBM AIX LSPath Unauthorized
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
local
low complexity
ibm
2.1
2004-11-03 CVE-2004-0828 Local File Corruption vulnerability in IBM CTSTRTCASD Utility
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
local
low complexity
ibm
2.1
2003-12-31 CVE-2003-1437 Unspecified vulnerability in BEA Weblogic Server 7.0/7.0.0.1
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
local
low complexity
hp ibm microsoft redhat sun bea
2.1
2002-12-31 CVE-2002-1687 Local Security vulnerability in AIX
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
local
low complexity
ibm
2.1