The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
AIX infod allows local users to gain root access through an X display.
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
Unauthorized privileged access or denial of service via dtappgather program in CDE.
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
Buffer overflow in AIX writesrv command allows local users to obtain root access.
Buffer overflow in AIX xdat gives root access to local users.
Buffer overflow in AIX rcp command allows local users to obtain root access.
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
Buffer overflow in AIX lchangelv gives root access.
Buffer overflow in AIX lquerylv program gives root access to local users.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Buffer overflow in AIX dtterm program for the CDE.
Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in NLS (Natural Language Service).
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.