cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 10 of 27
CVE-1999-0014P4HIGHCVSS 7.2PoCv4.1v4.2+1 more1998-01-21
CVE-1999-0014 [HIGH] CVE-1999-0014: Unauthorized privileged access or denial of service via dtappgather program in CDE. Unauthorized privileged access or denial of service via dtappgather program in CDE.
nvd
CVE-2024-47115P3HIGHCVSS 7.8v7.2v7.3+1 more2024-12-07
CVE-2024-47115 [HIGH] CWE-78 CVE-2024-47115: IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
nvd
CVE-2026-16958P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16958 [HIGH] CWE-787 CVE-2026-16958: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
nvd
CVE-2026-16706P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16706 [HIGH] CWE-787 CVE-2026-16706: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
nvd
CVE-1999-0112P4HIGHCVSS 7.2PoCv4.1v4.21997-05-01
CVE-1999-0112 [HIGH] CVE-1999-0112: Buffer overflow in AIX dtterm program for the CDE. Buffer overflow in AIX dtterm program for the CDE.
nvd
CVE-2005-2232P4MEDIUMCVSS 4.6PoCv5.1v5.2+1 more2005-07-12
CVE-2005-2232 [MEDIUM] CVE-2005-2232: Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitr Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v4.3.3v5.1+1 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-2005-1037P3CRITICALCVSS 10.0v5.3.02005-05-02
CVE-2005-1037 [CRITICAL] CVE-2005-1037: Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gai Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.
nvd
CVE-2020-4829P3HIGHCVSS 7.8v7.1v7.22020-12-10
CVE-2020-4829 [HIGH] CVE-2020-4829: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user c IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.
nvd
CVE-2021-29801P3HIGHCVSS 7.8v7.1v7.22021-08-26
CVE-2021-29801 [HIGH] CVE-2021-29801: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.
nvd
CVE-2021-29741P3HIGHCVSS 7.8v7.1v7.22021-08-02
CVE-2021-29741 [HIGH] CVE-2021-29741: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ks IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.
nvd
CVE-2023-45166P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45166 [HIGH] CVE-2023-45166: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.
nvd
CVE-2022-36768P3HIGHCVSS 7.8v7.1v7.2+1 more2022-09-13
CVE-2022-36768 [HIGH] CVE-2022-36768: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.
nvd
CVE-2022-34356P3HIGHCVSS 7.8v7.1v7.2+1 more2022-09-13
CVE-2022-34356 [HIGH] CVE-2022-34356: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.
nvd
CVE-2026-16928P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16928 [HIGH] CWE-122 CVE-2026-16928: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
nvd
CVE-2026-19448P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-19448 [HIGH] CWE-908 CVE-2026-19448: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.
nvd
CVE-1999-0116P4MEDIUMCVSS 5.0PoCv3.2.5v4.1+1 more1996-09-19
CVE-1999-0116 [MEDIUM] CVE-1999-0116: Denial of service when an attacker sends many SYN packets to create multiple connections without eve Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.
nvd
CVE-2004-2697P4MEDIUMCVSS 6.9PoCv4.3.3v5.1+1 more2004-12-31
CVE-2004-2697 [MEDIUM] CWE-362 CVE-2004-2697: The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
nvd
CVE-2022-22351P3HIGHCVSS 8.6≥ 7.1.5.0, ≤ 7.1.5.37≥ 7.2.4.0, ≤ 7.2.4.4+8 more2022-03-07
CVE-2022-22351 [HIGH] CVE-2022-22351: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vuln IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396
nvd
CVE-2017-1093P3HIGHCVSS 7.8v6.1v7.1+1 more2017-02-02
CVE-2017-1093 [HIGH] CVE-2017-1093: IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
nvd
Ibm Aix vulnerabilities | cvebase