<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM AIX (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ibm-aix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-aix-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM AIX (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-36251 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36251</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36251</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36250 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36250</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36250</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls.  This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36236 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36236</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36236</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36096 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36096</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36096</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36244 – IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36244</guid>
    <pubDate>Tue, 16 Sep 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36244</strong></p>
  <p>IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-454</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33112 – IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33112</guid>
    <pubDate>Tue, 10 Jun 2025 17:23:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33112</strong></p>
  <p>IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56347 – IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56347</guid>
    <pubDate>Tue, 18 Mar 2025 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56347</strong></p>
  <p>IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56346 – IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56346</guid>
    <pubDate>Tue, 18 Mar 2025 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56346</strong></p>
  <p>IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47115 – IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47115</guid>
    <pubDate>Sat, 07 Dec 2024 13:19:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47115</strong></p>
  <p>IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27260 – IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27260</guid>
    <pubDate>Thu, 16 May 2024 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27260</strong></p>
  <p>IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  283985.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27273 – IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27273</guid>
    <pubDate>Tue, 07 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27273</strong></p>
  <p>IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation.  IBM X-Force ID:  284903.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25021 – IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25021</guid>
    <pubDate>Thu, 22 Feb 2024 12:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25021</strong></p>
  <p>IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands.  IBM X-Force ID:  281320.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45174 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45174</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45174</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service.  IBM X-Force ID:  267972.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45170 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45170</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45170</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service.  IBM X-Force ID:  267968.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45166 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45166</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45166</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges.  IBM X-Force ID:  267964.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45168 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45168</guid>
    <pubDate>Fri, 01 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45168</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  267966.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28528 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28528</guid>
    <pubDate>Fri, 28 Apr 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28528</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  251207.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26286 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26286</guid>
    <pubDate>Wed, 26 Apr 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26286</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands.  IBM X-Force ID:  248421.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41290 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41290</guid>
    <pubDate>Fri, 23 Dec 2022 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41290</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges.  IBM X-Force ID:  236690.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36768 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36768</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36768</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34356 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34356</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34356</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22351 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22351</guid>
    <pubDate>Mon, 07 Mar 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22351</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38991 – IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38991</guid>
    <pubDate>Tue, 11 Jan 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38991</strong></p>
  <p>IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38990 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38990</guid>
    <pubDate>Mon, 10 Jan 2022 14:10:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38990</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29801 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29801</guid>
    <pubDate>Thu, 26 Aug 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29801</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29741 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29741</guid>
    <pubDate>Mon, 02 Aug 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29741</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29706 – IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29706</guid>
    <pubDate>Thu, 17 Jun 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29706</strong></p>
  <p>IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4829 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4829</guid>
    <pubDate>Thu, 10 Dec 2020 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4829</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1692 – IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1692</guid>
    <pubDate>Wed, 07 Feb 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1692</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8972 – IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8972</guid>
    <pubDate>Wed, 15 Feb 2017 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8972</strong></p>
  <p>IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6079 – IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6079</guid>
    <pubDate>Wed, 15 Feb 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6079</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1093 – IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1093</guid>
    <pubDate>Thu, 02 Feb 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1093</strong></p>
  <p>IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3053 – IBM AIX contains an unspecified vulnerability that would allow a locally authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3053</guid>
    <pubDate>Wed, 01 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3053</strong></p>
  <p>IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8904 – lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8904</guid>
    <pubDate>Thu, 15 Jan 2015 22:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8904</strong></p>
  <p>lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3074 – The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3074</guid>
    <pubDate>Wed, 02 Jul 2014 10:35:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3074</strong></p>
  <p>The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4011 – Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4011</guid>
    <pubDate>Thu, 18 Jul 2013 16:51:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4011</strong></p>
  <p>Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3005 – The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3005</guid>
    <pubDate>Sat, 06 Jul 2013 13:57:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3005</strong></p>
  <p>The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3035 – The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3035</guid>
    <pubDate>Fri, 21 Jun 2013 14:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3035</strong></p>
  <p>The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2200 – The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2200</guid>
    <pubDate>Wed, 27 Jun 2012 10:18:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2200</strong></p>
  <p>The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0745 – The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0745</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0745</strong></p>
  <p>The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1385 – IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1385</guid>
    <pubDate>Fri, 02 Mar 2012 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1385</strong></p>
  <p>IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0194 – The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0194</guid>
    <pubDate>Mon, 06 Feb 2012 20:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0194</strong></p>
  <p>The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-3187 – Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3187</guid>
    <pubDate>Mon, 30 Aug 2010 20:00:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-3187</strong></p>
  <p>Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1039 – Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1039</guid>
    <pubDate>Thu, 20 May 2010 17:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1039</strong></p>
  <p>Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1124 – bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1124</guid>
    <pubDate>Fri, 26 Mar 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1124</strong></p>
  <p>bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0961 – Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0961</guid>
    <pubDate>Wed, 10 Mar 2010 22:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0961</strong></p>
  <p>Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0960 – Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0960</guid>
    <pubDate>Wed, 10 Mar 2010 22:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0960</strong></p>
  <p>Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0922 – Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0922</guid>
    <pubDate>Wed, 03 Mar 2010 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0922</strong></p>
  <p>Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors.  NOTE: some of these details are obtained from third party information.  NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official service pack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4362 – Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4362</guid>
    <pubDate>Mon, 21 Dec 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4362</strong></p>
  <p>Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4361 – Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4361</guid>
    <pubDate>Mon, 21 Dec 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4361</strong></p>
  <p>Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3699 – Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3699</guid>
    <pubDate>Thu, 15 Oct 2009 10:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3699</strong></p>
  <p>Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3517 – nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3517</guid>
    <pubDate>Thu, 01 Oct 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3517</strong></p>
  <p>nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3516 – gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3516</guid>
    <pubDate>Thu, 01 Oct 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3516</strong></p>
  <p>gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2727 – Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2727</guid>
    <pubDate>Mon, 10 Aug 2009 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2727</strong></p>
  <p>Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2669 – A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2669</guid>
    <pubDate>Wed, 05 Aug 2009 19:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2669</strong></p>
  <p>A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2434 – Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2434</guid>
    <pubDate>Mon, 13 Jul 2009 14:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2434</strong></p>
  <p>Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1954 – Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1954</guid>
    <pubDate>Mon, 08 Jun 2009 01:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1954</strong></p>
  <p>Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1355 – Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1355</guid>
    <pubDate>Tue, 21 Apr 2009 16:24:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1355</strong></p>
  <p>Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0779 – Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0779</guid>
    <pubDate>Wed, 04 Mar 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0779</strong></p>
  <p>Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0370 – Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0370</guid>
    <pubDate>Fri, 30 Jan 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0370</strong></p>
  <p>Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4018 – swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4018</guid>
    <pubDate>Thu, 11 Sep 2008 01:13:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4018</strong></p>
  <p>swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors.  NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-6717 – Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6717</guid>
    <pubDate>Thu, 11 Sep 2008 01:04:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-6717</strong></p>
  <p>Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2513 – Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2513</guid>
    <pubDate>Mon, 02 Jun 2008 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2513</strong></p>
  <p>Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2515 – Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2515</guid>
    <pubDate>Mon, 02 Jun 2008 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2515</strong></p>
  <p>Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1710 – Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1710</guid>
    <pubDate>Wed, 09 Apr 2008 19:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1710</strong></p>
  <p>Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1593 – The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1593</guid>
    <pubDate>Mon, 31 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1593</strong></p>
  <p>The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1596 – Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1596</guid>
    <pubDate>Mon, 31 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1596</strong></p>
  <p>Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1599 – The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1599</guid>
    <pubDate>Mon, 31 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1599</strong></p>
  <p>The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1600 – The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle enviro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1600</guid>
    <pubDate>Mon, 31 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1600</strong></p>
  <p>The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1601 – Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1601</guid>
    <pubDate>Mon, 31 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1601</strong></p>
  <p>Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0584 – Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0584</guid>
    <pubDate>Tue, 05 Feb 2008 03:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0584</strong></p>
  <p>Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0586 – Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0586</guid>
    <pubDate>Tue, 05 Feb 2008 03:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0586</strong></p>
  <p>Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0587 – Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0587</guid>
    <pubDate>Tue, 05 Feb 2008 03:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0587</strong></p>
  <p>Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0588 – Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0588</guid>
    <pubDate>Tue, 05 Feb 2008 03:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0588</strong></p>
  <p>Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5764 – Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5764</guid>
    <pubDate>Fri, 25 Jan 2008 01:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5764</strong></p>
  <p>Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4217 – Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4217</guid>
    <pubDate>Mon, 05 Nov 2007 16:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4217</strong></p>
  <p>Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4513 – Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4513</guid>
    <pubDate>Mon, 05 Nov 2007 16:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4513</strong></p>
  <p>Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4621 – Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4621</guid>
    <pubDate>Mon, 05 Nov 2007 16:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4621</strong></p>
  <p>Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4622 – Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4622</guid>
    <pubDate>Mon, 05 Nov 2007 16:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4622</strong></p>
  <p>Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4623 – Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4623</guid>
    <pubDate>Mon, 05 Nov 2007 16:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4623</strong></p>
  <p>Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4791 – Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4791</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4791</strong></p>
  <p>Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4792 – Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4792</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4792</strong></p>
  <p>Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4793 – Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4793</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4793</strong></p>
  <p>Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4794 – Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4794</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4794</strong></p>
  <p>Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4795 – Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4795</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4795</strong></p>
  <p>Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4796 – Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4796</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4796</strong></p>
  <p>Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4797 – Multiple buffer overflows in unspecified svprint (System V print) commands in bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4797</guid>
    <pubDate>Mon, 10 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4797</strong></p>
  <p>Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4354 – Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4354</guid>
    <pubDate>Wed, 15 Aug 2007 00:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4354</strong></p>
  <p>Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4355 – Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4355</guid>
    <pubDate>Wed, 15 Aug 2007 00:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4355</strong></p>
  <p>Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-3680 – Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3680</guid>
    <pubDate>Wed, 11 Jul 2007 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-3680</strong></p>
  <p>Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1798 – Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1798</guid>
    <pubDate>Mon, 02 Apr 2007 22:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1798</strong></p>
  <p>Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0978 – Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0978</guid>
    <pubDate>Fri, 16 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0978</strong></p>
  <p>Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0618 – Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0618</guid>
    <pubDate>Wed, 31 Jan 2007 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0618</strong></p>
  <p>Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5005 – Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5005</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5005</strong></p>
  <p>Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5006 – Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5006</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5006</strong></p>
  <p>Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-5008 – Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5008</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-5008</strong></p>
  <p>Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5009 – Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5009</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5009</strong></p>
  <p>Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5010 – Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5010</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5010</strong></p>
  <p>Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5011 – Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5011</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5011</strong></p>
  <p>Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5003 – Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5003</guid>
    <pubDate>Wed, 27 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5003</strong></p>
  <p>Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5003">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
