Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
AIX bugfiler program allows local users to gain root access.
AIX passwd allows local users to gain root access.
AIX infod allows local users to gain root access through an X display.
Buffer overflow in AIX lquerylv program gives root access to local users.
Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.