Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 11 of 19
CVE-2006-5010P4HIGHCVSS 7.2v5.3.02006-09-27
CVE-2006-5010 [HIGH] CVE-2006-5010: Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitr
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
nvd
CVE-2002-1548P4HIGHCVSS 7.2v4.3.02003-03-31
CVE-2002-1548 [HIGH] CVE-2002-1548: Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execut
Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
nvd
CVE-2009-3516P4HIGHCVSS 7.2v5.3.0v5.3.7+5 more2009-10-01
CVE-2009-3516 [HIGH] CWE-255 CVE-2009-3516: gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerbe
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
nvd
CVE-2008-0584P4HIGHCVSS 7.2v5.2v5.32008-02-05
CVE-2008-0584 [HIGH] CWE-264 CVE-2008-0584: Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privil
Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.
nvd
CVE-2007-4797P4HIGHCVSS 7.2v5.2v5.32007-09-10
CVE-2007-4797 [HIGH] CWE-119 CVE-2007-4797: Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM
Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4792P4HIGHCVSS 7.2v5.32007-09-10
CVE-2007-4792 [HIGH] CWE-119 CVE-2007-4792: Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain pri
Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-1999-0017P4HIGHCVSS 7.5v3.2v4.1+2 more1997-12-10
CVE-1999-0017 [HIGH] CVE-1999-0017: FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP clien
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
nvd
CVE-2002-0744P4CRITICALCVSS 10.0v4.3.32002-08-12
CVE-2002-0744 [CRITICAL] CVE-2002-0744: namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a bu
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
nvd
CVE-1999-0835P4CRITICALCVSS 10.0v4.31999-11-10
CVE-1999-0835 [CRITICAL] CVE-1999-0835: Denial of service in BIND named via malformed SIG records.
Denial of service in BIND named via malformed SIG records.
nvd
CVE-2018-1655P4MEDIUMCVSS 5.5v5.3v6.1+2 more2018-06-22
CVE-2018-1655 [MEDIUM] CWE-200 CVE-2018-1655: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to ex
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
nvd
CVE-1999-0022P4HIGHCVSS 7.8v3.1v3.2+9 more1996-07-03
CVE-1999-0022 [HIGH] CWE-125 CVE-1999-0022: Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
nvd
CVE-1999-0138P4HIGHCVSS 7.2v3.2.5v41996-06-26
CVE-1999-0138 [HIGH] CVE-1999-0138: The suidperl and sperl program do not give up root privileges when changing UIDs back to the origina
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
nvd
CVE-2005-4271P4HIGHCVSS 7.2v5.3v5.3_l2005-12-15
CVE-2005-4271 [HIGH] CVE-2005-4271: Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary co
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
nvd
CVE-2003-0954P4HIGHCVSS 7.2v4.3.3v5.1+1 more2003-12-31
CVE-2003-0954 [HIGH] CVE-2003-0954: Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
nvd
CVE-2003-0257P4HIGHCVSS 7.2v4.3v4.3.1+4 more2004-04-15
CVE-2003-0257 [HIGH] CVE-2003-0257: Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local user
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
nvd
CVE-1999-1487P4HIGHCVSS 7.2v4.1v4.1.1+7 more1998-01-21
CVE-1999-1487 [HIGH] CVE-1999-1487: Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or mo
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
nvd
CVE-2008-2515P4HIGHCVSS 7.2v5.2v5.3+1 more2008-06-02
CVE-2008-2515 [HIGH] CWE-264 CVE-2008-2515: Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileg
Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."
nvd
CVE-2007-4236P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4236 [MEDIUM] CVE-2007-4236: Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group p
Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.
nvd
CVE-2007-4237P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4237 [MEDIUM] CVE-2007-4237: Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows loc
Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.
nvd
CVE-2002-0746P4CRITICALCVSS 10.0v4.3.32002-08-12
CVE-2002-0746 [CRITICAL] CVE-2002-0746: Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
nvd