cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 12 of 27
CVE-2026-16837P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16837 [HIGH] CWE-400 CVE-2026-16837: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
nvd
CVE-2000-1119P4MEDIUMCVSS 4.6PoCv4.2v4.2.1+4 more2001-01-09
CVE-2000-1119 [MEDIUM] CVE-2000-1119: Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitr Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
nvd
CVE-1999-0099P3CRITICALCVSS 10.0v3.2v4.11995-10-19
CVE-1999-0099 [CRITICAL] CVE-1999-0099: Buffer overflow in syslog utility allows local or remote attackers to gain root privileges. Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
nvd
CVE-2003-0170P3CRITICALCVSS 10.0v5.22004-03-29
CVE-2003-0170 [CRITICAL] CVE-2003-0170: Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
nvd
CVE-2003-0784P3CRITICALCVSS 10.0v4.3.3v5.1+1 more2003-10-06
CVE-2003-0784 [CRITICAL] CVE-2003-0784: Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attacke Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
nvd
CVE-2017-1692P3HIGHCVSS 7.8v5.3v6.1+2 more2018-02-07
CVE-2017-1692 [HIGH] CVE-2017-1692: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally auth IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.
nvd
CVE-2023-45170P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45170 [HIGH] CVE-2023-45170: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.
nvd
CVE-2023-45174P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45174 [HIGH] CVE-2023-45174: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.
nvd
CVE-2002-0677P3HIGHCVSS 7.5v4.3.3v5.12002-07-23
CVE-2002-0677 [HIGH] CVE-2002-0677: CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory loca CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
nvd
CVE-2016-6038P3MEDIUMCVSS 6.5v5.3v6.1+1 more2016-09-26
CVE-2016-6038 [MEDIUM] CWE-22 CVE-2016-6038: Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI) Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
nvd
CVE-2026-16922P3HIGHCVSS 7.0≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16922 [HIGH] CWE-367 CVE-2026-16922: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-1999-0088P4CRITICALCVSS 10.0v4.31998-10-26
CVE-1999-0088 [CRITICAL] CVE-1999-0088: IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
nvd
CVE-2002-1621P4CRITICALCVSS 10.0v4.3v4.3.1+3 more2002-04-22
CVE-2002-1621 [CRITICAL] CVE-2002-1621: Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers t Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.
nvd
CVE-2026-16819P3HIGHCVSS 7.7≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16819 [HIGH] CWE-367 CVE-2026-16819: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.
nvd
CVE-2026-17159P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17159 [HIGH] CWE-190 CVE-2026-17159: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.
nvd
CVE-2026-16852P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16852 [HIGH] CWE-190 CVE-2026-16852: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.
nvd
CVE-1999-0097P4CRITICALCVSS 10.0v3.2v3.2.4+9 more1997-10-29
CVE-1999-0097 [CRITICAL] CVE-1999-0097: The AIX FTP client can be forced to execute commands from a malicious server through shell metachara The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
nvd
CVE-2026-0990P3MEDIUMCVSS 5.9≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0990 [MEDIUM] CWE-674 CVE-2026-0990: A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occur A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recu
nvd
CVE-2022-47990P3HIGHCVSS 7.8v7.1v7.2+2 more2023-01-18
CVE-2022-47990 [HIGH] CWE-120 CVE-2022-47990: IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerabi IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could result in a denial of service or arbitrary code execution. IBM X-Force ID: 243556.
nvd
CVE-2026-16851P3HIGHCVSS 7.4≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16851 [HIGH] CWE-416 CVE-2026-16851: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-after-free.
nvd
Ibm Aix vulnerabilities | cvebase