Page 3 of 59 results (0.002 seconds)

CVSS: 10.0EPSS: 27%CPEs: 87EXPL: 3

14 Aug 2001 — Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. • https://www.exploit-db.com/exploits/21018 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 10.0EPSS: 3%CPEs: 2EXPL: 1

19 Jun 2001 — diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program. • https://www.exploit-db.com/exploits/20965 •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 1

09 Jan 2001 — Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument. • https://www.exploit-db.com/exploits/20452 •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 1

09 Jan 2001 — Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands. • https://www.exploit-db.com/exploits/20453 •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 1

09 Jan 2001 — Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument. • https://www.exploit-db.com/exploits/20454 •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

09 Jan 2001 — Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument. • http://marc.info/?l=bugtraq&m=97569466809056&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

09 Jan 2001 — Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands. • http://marc.info/?l=bugtraq&m=97569466809056&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 1

09 Jan 2001 — Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables. • https://www.exploit-db.com/exploits/20455 •

CVSS: 10.0EPSS: 0%CPEs: 74EXPL: 13

14 Nov 2000 — Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.1EPSS: 0%CPEs: 5EXPL: 1

14 Nov 2000 — netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities. • https://www.exploit-db.com/exploits/20213 •