Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 12 of 19
CVE-2002-0743P4CRITICALCVSS 10.0v4.3.32002-08-12
CVE-2002-0743 [CRITICAL] CVE-2002-0743: mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buff
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
nvd
CVE-2002-1690P4CRITICALCVSS 10.0v3.2.52002-12-31
CVE-2002-1690 [CRITICAL] CVE-2002-1690: Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "securit
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
nvd
CVE-2004-0243P4MEDIUMCVSS 5.0≥ 4.3.3, ≤ 5.12004-11-23
CVE-2004-0243 [MEDIUM] CWE-203 CVE-2004-0243: AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
nvd
CVE-1999-1121P4HIGHCVSS 7.2≤ 3.21992-03-19
CVE-1999-1121 [HIGH] CVE-1999-1121: The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
nvd
CVE-1999-0627P4UNKNOWNCVSS 0.0v3.1v3.21992-03-01
CVE-1999-0627 [NONE] CVE-1999-0627: The rexd service is running, which uses weak authentication that can allow an attacker to execute co
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
nvd
CVE-1999-0318P4HIGHCVSS 7.2v41997-03-01
CVE-1999-0318 [HIGH] CVE-1999-0318: Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
nvd
CVE-2000-0466P4HIGHCVSS 7.2v4.3v4.3.1+1 more2000-06-20
CVE-2000-0466 [HIGH] CVE-2000-0466: AIX cdmount allows local users to gain root privileges via shell metacharacters.
AIX cdmount allows local users to gain root privileges via shell metacharacters.
nvd
CVE-2006-4416P4HIGHCVSS 7.2v5.1v5.2+1 more2006-08-28
CVE-2006-4416 [HIGH] CVE-2006-4416: Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.
nvd
CVE-2008-1596P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1596 [HIGH] CVE-2008-1596: Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.
nvd
CVE-2005-0240P4HIGHCVSS 7.2v5.22005-05-02
CVE-2005-0240 [HIGH] CVE-2005-0240: Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.
nvd
CVE-1999-1552P4HIGHCVSS 7.2≤ 3.2.5v3.1+2 more1994-07-20
CVE-1999-1552 [HIGH] CVE-1999-1552: dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check pri
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
nvd
CVE-2003-1018P4HIGHCVSS 7.2v4.3.3v5.1+1 more2004-03-29
CVE-2003-1018 [HIGH] CVE-2003-1018: Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq gr
Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.
nvd
CVE-2008-1710P4HIGHCVSS 7.2v6.12008-04-09
CVE-2008-1710 [HIGH] CWE-264 CVE-2008-1710: Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges
Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.
nvd
CVE-2013-5419P4MEDIUMCVSS 6.9v6.1v7.12013-10-04
CVE-2013-5419 [MEDIUM] CWE-119 CVE-2013-5419: Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 a
Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
nvd
CVE-2008-5384P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5384 [MEDIUM] CWE-264 CVE-2008-5384: crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cro
crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.
nvd
CVE-2010-3405P4MEDIUMCVSS 6.8v5.3v6.12010-09-16
CVE-2010-3405 [MEDIUM] CWE-119 CVE-2010-3405: Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1,
Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.
nvd
CVE-2008-5387P4MEDIUMCVSS 6.2v6.1v6.1.1+1 more2008-12-09
CVE-2008-5387 [MEDIUM] CWE-119 CVE-2008-5387: Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabl
Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.
nvd
CVE-1999-1574P4HIGHCVSS 7.5v4.3.01998-07-06
CVE-1999-1574 [HIGH] CVE-1999-1574: Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
nvd
CVE-1999-0903P4HIGHCVSS 7.5v4.3.21999-10-26
CVE-1999-0903 [HIGH] CVE-1999-0903: genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports gre
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
nvd
CVE-2004-1028P4HIGHCVSS 7.2v5.1v5.1l+5 more2005-01-10
CVE-2004-1028 [HIGH] CVE-2004-1028: Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local user
Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.
nvd