Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 13 of 19
CVE-2000-1123P4HIGHCVSS 7.2v4.3v4.3.1+2 more2001-01-09
CVE-2000-1123 [HIGH] CVE-2000-1123: Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbi
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
nvd
CVE-1999-0072P4HIGHCVSS 7.2v4.1v4.1.1+6 more1997-10-22
CVE-1999-0072 [HIGH] CVE-1999-0072: Buffer overflow in AIX xdat gives root access to local users.
Buffer overflow in AIX xdat gives root access to local users.
nvd
CVE-2001-0533P4HIGHCVSS 7.2v4.3v5.12001-08-14
CVE-2001-0533 [HIGH] CVE-2001-0533: Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileg
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.
nvd
CVE-1999-0117P4HIGHCVSS 7.2v3.1v3.21992-03-31
CVE-1999-0117 [HIGH] CVE-1999-0117: AIX passwd allows local users to gain root access.
AIX passwd allows local users to gain root access.
nvd
CVE-2009-4362P4HIGHCVSS 7.2v6.12009-12-21
CVE-2009-4362 [HIGH] CWE-119 CVE-2009-4362: Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (a
Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments. NOTE: some of these details are obtained from third party information.
nvd
CVE-2016-0281P4LOWCVSS 3.7v5.3v6.1+2 more2016-08-08
CVE-2016-0281 [LOW] CWE-20 CVE-2016-0281: The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
nvd
CVE-2008-5386P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5386 [MEDIUM] CWE-119 CVE-2008-5386: Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows loca
Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4238P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4238 [MEDIUM] CVE-2007-4238: AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with
AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
nvd
CVE-2003-0914P4MEDIUMCVSS 4.3v5.1l2003-12-15
CVE-2003-0914 [MEDIUM] CVE-2003-0914: ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
nvd
CVE-2009-0536P4MEDIUMCVSS 4.9v5.2.0v5.3.0+6 more2009-02-11
CVE-2009-0536 [MEDIUM] CWE-264 CVE-2009-0536: at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
nvd
CVE-2000-1216P4HIGHCVSS 7.2v4.3.02000-01-27
CVE-2000-1216 [HIGH] CWE-120 CVE-2000-1216: Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root priv
Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.
nvd
CVE-2001-1329P4HIGHCVSS 7.2v4.2.02001-06-11
CVE-2001-1329 [HIGH] CVE-2001-1329: Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long comma
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
nvd
CVE-2001-1330P4HIGHCVSS 7.2v4.2.02001-06-11
CVE-2001-1330 [HIGH] CVE-2001-1330: Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long comma
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
nvd
CVE-1999-0089P4HIGHCVSS 7.2v4.31997-10-28
CVE-1999-0089 [HIGH] CVE-1999-0089: Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
nvd
CVE-2009-4361P4HIGHCVSS 7.2v6.12009-12-21
CVE-2009-4361 [HIGH] CWE-119 CVE-2009-4361: Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (
Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument. NOTE: some of these details are obtained from third party information.
nvd
CVE-2007-0670P4MEDIUMCVSS 4.6v5.2v5.32007-02-03
CVE-2007-0670 [MEDIUM] CWE-119 CVE-2007-0670: Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code
Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.
nvd
CVE-2015-4948P4MEDIUMCVSS 6.9v5.3v6.1+1 more2015-10-16
CVE-2015-4948 [MEDIUM] CWE-264 CVE-2015-4948: netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows lo
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-5385P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5385 [MEDIUM] CWE-264 CVE-2008-5385: enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfi
enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.
nvd
CVE-2007-5804P4MEDIUMCVSS 6.9v5.2v5.32007-11-05
CVE-2007-5804 [MEDIUM] CVE-2007-5804: cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons,
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
nvd
CVE-2003-0285P4MEDIUMCVSS 5.0≤ 5.22003-06-16
CVE-2003-0285 [MEDIUM] CVE-2003-0285: IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) pr
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
nvd