cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 1 of 19
CVE-2001-0797P2CRITICALCVSS 10.0ExploitedPoCv4.3v4.3.1+3 more2001-12-12
CVE-2001-0797 [CRITICAL] CVE-2001-0797: Buffer overflow in login in various System V based operating systems allows remote attackers to exec Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
nvd
CVE-2003-0694P2CRITICALCVSS 10.0ExploitedPoCv4.3.3v5.1+1 more2003-10-06
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
nvd
CVE-2001-0554P2CRITICALCVSS 10.0ExploitedPoCv4.3v4.3.1+3 more2001-08-14
CVE-2001-0554 [CRITICAL] CWE-120 CVE-2001-0554: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attack Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
nvd
CVE-2003-0681P2HIGHCVSS 7.5ExploitedPoCv4.3.3v5.1+1 more2003-10-06
CVE-2003-0681 [HIGH] CVE-2003-0681: A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rul A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
nvd
CVE-2002-1689P2CRITICALCVSS 10.0Exploitedv3.2.52002-12-31
CVE-2002-1689 [CRITICAL] CVE-2002-1689: Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
nvd
CVE-2009-3699P2CRITICALCVSS 10.0PoCv5v5.1+23 more2009-10-15
CVE-2009-3699 [CRITICAL] CWE-119 CVE-2009-3699: Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3 Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
nvd
CVE-2010-1039P2CRITICALCVSS 10.0PoC≤ 5.3v1.2.1+35 more2010-05-20
CVE-2010-1039 [CRITICAL] CWE-134 CVE-2010-1039: Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid direct
nvd
CVE-2009-2727P2CRITICALCVSS 9.3PoCv5.2v5.2.0+14 more2009-08-10
CVE-2009-2727 [CRITICAL] CWE-119 CVE-2009-2727: Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.
nvd
CVE-2010-3187P2CRITICALCVSS 10.0PoC≤ 5.32010-08-30
CVE-2010-3187 [CRITICAL] CWE-119 CVE-2010-3187: Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
nvd
CVE-2014-3566P3LOWCVSS 3.4PoCv5.3v6.1+1 more2014-10-15
CVE-2014-3566 [LOW] CWE-310 CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
nvd
CVE-1999-0046P3CRITICALCVSS 10.0PoCv3.2v4.1+5 more1997-02-06
CVE-1999-0046 [CRITICAL] CWE-120 CVE-1999-0046: Buffer overflow of rlogin program using TERM environmental variable. Buffer overflow of rlogin program using TERM environmental variable.
nvd
CVE-1999-0003P3CRITICALCVSS 10.0PoCv4.1v4.1.1+7 more1998-04-01
CVE-1999-0003 [CRITICAL] CVE-1999-0003: Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
nvd
CVE-1999-0113P3CRITICALCVSS 10.0PoCv3.1v3.2+2 more1994-05-23
CVE-1999-0113 [CRITICAL] CWE-88 CVE-1999-0113: Some implementations of rlogin allow root access if given a -froot parameter. Some implementations of rlogin allow root access if given a -froot parameter.
nvd
CVE-2023-28528P3HIGHCVSS 7.8PoCv7.1v7.2+2 more2023-04-28
CVE-2023-28528 [HIGH] CWE-78 CVE-2023-28528: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.
nvd
CVE-2024-56346P2CRITICALCVSS 10.0v7.2v7.32025-03-18
CVE-2024-56346 [CRITICAL] CWE-114 CVE-2024-56346: IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary co IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
nvd
CVE-1999-0009P3CRITICALCVSS 10.0PoCv4.1v4.1.1+7 more1998-04-08
CVE-1999-0009 [CRITICAL] CVE-1999-0009: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
nvd
CVE-2016-8972P3HIGHCVSS 7.8PoCv6.1v7.1+1 more2017-02-15
CVE-2016-8972 [HIGH] CWE-264 CVE-2016-8972: IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
nvd
CVE-1999-0208P3CRITICALCVSS 10.0PoCv3.2v4.11995-12-12
CVE-1999-0208 [CRITICAL] CVE-1999-0208: rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
nvd
CVE-2000-0844P3CRITICALCVSS 10.0PoCv3.2v3.2.4+13 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2016-6079P3HIGHCVSS 7.8PoCv5.3v6.1+2 more2017-02-15
CVE-2016-6079 [HIGH] CWE-264 CVE-2016-6079: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally auth IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
nvd
1 / 19Next →
Ibm Aix vulnerabilities | cvebase