← Vulnerability feed

Vulnerability record · CVE-2010-3187 · published 30 August 2010

CVE-2010-3187: Ibm aix memory buffer overflow vulnerability

Ibm · Aix

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

10.0 CVSS 2.0 High EPSS 20% · top 2.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aix.software.ibm.com/aix/efixes/security/ftpd_advisory.asc PatchVendor Advisory
http://seclists.org/fulldisclosure/2010/Jul/281 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/317 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/324 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/337 Mailing ListThird Party Advisory
http://securitytracker.com/id?1024368 Third Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/14409/ ExploitThird Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/14456/ ExploitThird Party AdvisoryVDB Entry
http://www.ibm.com/support/docview.wss?uid=isg1IZ83252 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83274 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83275 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83276 Vendor Advisory
http://www.osvdb.org/66576 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11697 Third Party Advisory
http://aix.software.ibm.com/aix/efixes/security/ftpd_advisory.asc PatchVendor Advisory
http://seclists.org/fulldisclosure/2010/Jul/281 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/317 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/324 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2010/Jul/337 Mailing ListThird Party Advisory
http://securitytracker.com/id?1024368 Third Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/14409/ ExploitThird Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/14456/ ExploitThird Party AdvisoryVDB Entry
http://www.ibm.com/support/docview.wss?uid=isg1IZ83252 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83274 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83275 Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=isg1IZ83276 Vendor Advisory
http://www.osvdb.org/66576 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11697 Third Party Advisory

Track CVE-2010-3187 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-56346Ibm aix vulnerabilityIBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.EPSS 1.1%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2009-3699IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflowA stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and…EPSS 62%analysed10.0CVE-2009-3517Ibm aix vulnerabilitynfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…EPSS 4.4%10.0CVE-2006-5008Ibm aix vulnerabilityUnspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspec…EPSS 3.5%10.0CVE-2005-4272Ibm aix vulnerabilityMultiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.EPSS 9.0%10.0CVE-2005-1037Ibm aix vulnerabilityUnknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.EPSS 2.4%10.0CVE-2004-2388Ibm aix vulnerabilityrexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten b…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2010-3187), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.