← Vulnerability feed

Vulnerability record · CVE-2004-2388 · published 31 December 2004

CVE-2004-2388: Ibm aix vulnerability

Ibm · Aix

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

10.0 CVSS 2.0 High EPSS 2.1% · top 18.7%
10.0CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2388 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-56346Ibm aix vulnerabilityIBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.EPSS 1.1%10.0CVE-2010-3187Ibm aix memory buffer overflow vulnerabilityBuffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.EPSS 20%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2009-3699IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflowA stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and…EPSS 62%analysed10.0CVE-2009-3517Ibm aix vulnerabilitynfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…EPSS 4.4%10.0CVE-2006-5008Ibm aix vulnerabilityUnspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspec…EPSS 3.5%10.0CVE-2005-4272Ibm aix vulnerabilityMultiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.EPSS 9.0%10.0CVE-2005-1037Ibm aix vulnerabilityUnknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2004-2388), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.