cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 13 of 27
CVE-2026-16927P3HIGHCVSS 7.0≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16927 [HIGH] CWE-367 CVE-2026-16927: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2011-1385P4HIGHCVSS 7.8v5.3v6.1+1 more2012-03-02
CVE-2011-1385 [HIGH] CWE-399 CVE-2011-1385: IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of se IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.
nvd
CVE-2026-16914P3MEDIUMCVSS 6.7≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16914 [MEDIUM] CWE-787 CVE-2026-16914: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2026-16951P3MEDIUMCVSS 6.7≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16951 [MEDIUM] CWE-787 CVE-2026-16951: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-16964P3MEDIUMCVSS 6.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16964 [MEDIUM] CWE-200 CVE-2026-16964: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.
nvd
CVE-2014-0899P4MEDIUMCVSS 6.5v7.1.1v7.1.22014-03-11
CVE-2014-0899 [MEDIUM] CWE-264 CVE-2014-0899: ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
nvd
CVE-2026-16935P3HIGHCVSS 7.0≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16935 [HIGH] CWE-367 CVE-2026-16935: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2009-1355P4HIGHCVSS 7.2v5.2v5.3+1 more2009-04-21
CVE-2009-1355 [HIGH] CWE-119 CVE-2009-1355: Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privi Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.
nvd
CVE-1999-1117P4LOWCVSS 2.1PoCv4.1v4.21999-12-31
CVE-1999-1117 [LOW] CVE-1999-1117: lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
nvd
CVE-2005-3396P4HIGHCVSS 7.5v5.1v5.1l+5 more2005-11-01
CVE-2005-3396 [HIGH] CVE-2005-3396: Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
nvd
CVE-2006-0133P4LOWCVSS 3.6PoCv5.3_ml032006-01-09
CVE-2006-0133 [LOW] CVE-2006-0133: Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the exis Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
nvd
CVE-2026-16833P4MEDIUMCVSS 5.3≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16833 [MEDIUM] CWE-125 CVE-2026-16833: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.
nvd
CVE-2026-16838P4HIGHCVSS 7.0≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16838 [HIGH] CWE-367 CVE-2026-16838: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2007-4623P4HIGHCVSS 7.2v5.2v5.32007-11-05
CVE-2007-4623 [HIGH] CWE-119 CVE-2007-4623: Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.
nvd
CVE-2008-1601P4HIGHCVSS 7.2v5.2v5.32008-03-31
CVE-2008-1601 [HIGH] CWE-119 CVE-2008-1601: Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the s Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.
nvd
CVE-2000-0873P4LOWCVSS 2.1PoCv4.2v4.2.1+3 more2000-11-14
CVE-2000-0873 [LOW] CVE-2000-0873: netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users t netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
nvd
CVE-1999-0085P4HIGHCVSS 7.5v4.21996-08-21
CVE-1999-0085 [HIGH] CVE-1999-0085: Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbit Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
nvd
CVE-2005-3504P4HIGHCVSS 7.5v5.2v5.2.2+1 more2005-11-05
CVE-2005-3504 [HIGH] CVE-2005-3504: Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to c Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.
nvd
CVE-2003-0064P4HIGHCVSS 7.5v4.3v4.3.1+4 more2003-03-03
CVE-2003-0064 [HIGH] CVE-2003-0064: The dtterm terminal emulator allows attackers to modify the window title via a certain character esc The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
nvd
CVE-2002-0678P4HIGHCVSS 7.2v4.3.3v5.12002-07-23
CVE-2002-0678 [HIGH] CVE-2002-0678: CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a syml CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
nvd
Ibm Aix vulnerabilities | cvebase