Vulnerabilities > IBM > AIX > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-06-08 CVE-2014-3977 Link Following vulnerability in IBM AIX and Vios
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
ibm CWE-59
6.9
2014-05-08 CVE-2014-0930 Unspecified vulnerability in IBM AIX and Vios
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
local
ibm
4.7
2014-03-11 CVE-2014-0899 Permissions, Privileges, and Access Controls vulnerability in IBM AIX 7.1.1/7.1.2
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
network
low complexity
ibm CWE-264
6.5
2013-10-04 CVE-2013-5419 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 6.1/7.1
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
local
ibm CWE-119
6.9
2012-10-20 CVE-2012-4845 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
network
low complexity
ibm CWE-264
6.8
2012-09-14 CVE-2012-4817 Unspecified vulnerability in IBM AIX and Vios
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
ibm
5.0
2012-07-30 CVE-2012-0723 Improper Input Validation vulnerability in IBM AIX and Vios
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
local
low complexity
ibm CWE-20
4.9
2012-06-22 CVE-2012-2179 Permissions, Privileges, and Access Controls vulnerability in IBM AIX 5.3/6.1/7.1
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
ibm CWE-264
6.9
2012-06-20 CVE-2012-2192 Resource Management Errors vulnerability in IBM AIX and Vios
The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
local
low complexity
ibm CWE-399
4.9
2012-01-04 CVE-2011-1384 Link Following vulnerability in IBM Invscout.Rte
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
local
high complexity
ibm CWE-59
4.0