Unix

IBM AIX 7.3 — CVE-2003-0681 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2003-0681 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 15 October 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2003-0681, IBM PSIRT advisory page CVE: CVE-2003-0681 NVD summary: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope […]

Read more
IBM AIX 7.3 — CVE-2007-4938 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2007-4938 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 12 October 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2007-4938, IBM PSIRT advisory page CVE: CVE-2007-4938 NVD summary: Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly […]

Read more
IBM AIX 7.2 — CVE-2022-35721 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2022-35721 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 11 October 2022 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2022-35721, IBM Support Bulletin CVE: CVE-2022-35721 NVD summary: IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web […]

Read more
IBM AIX 7.1 — CVE-2022-35717 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-35717 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 11 October 2022 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-35717, IBM Support Bulletin CVE: CVE-2022-35717 NVD summary: "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. […]

Read more
CHAT