Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Format string vulnerability in the msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.3109 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
Buffer overflow in xlock program allows local users to execute commands as root.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
Buffer overflow in NLS (Natural Language Service).
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Buffer overflows in Sun libnsl allow root access.
Buffer overflow in AIX xdat gives root access to local users.
Buffer overflow in AIX lquerylv program gives root access to local users.
Unauthorized privileged access or denial of service via dtappgather program in CDE.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Buffer overflow in AIX rcp command allows local users to obtain root access.
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Buffer overflow in AIX lchangelv gives root access.