cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 14 of 27
CVE-2013-3035P4HIGHCVSS 7.1v6.1v7.12013-06-21
CVE-2013-3035 [HIGH] CWE-20 CVE-2013-3035: The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
nvd
CVE-2026-16827P4MEDIUMCVSS 5.9≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16827 [MEDIUM] CWE-908 CVE-2026-16827: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
nvd
CVE-1999-0687P4HIGHCVSS 7.5v4.1v4.1.1+9 more1999-09-13
CVE-1999-0687 [HIGH] CVE-1999-0687: The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execut The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
nvd
CVE-2010-0922P4HIGHCVSS 7.8v5.32010-03-03
CVE-2010-0922 [HIGH] CVE-2010-0922: Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to caus Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors. NOTE: some of these details are obtained from third party information. NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official s
nvd
CVE-2007-4513P4HIGHCVSS 7.2v5.2v5.32007-11-05
CVE-2007-4513 [HIGH] CWE-119 CVE-2007-4513: Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges vi Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
nvd
CVE-2012-4845P4MEDIUMCVSS 6.8v6.1v7.12012-10-20
CVE-2012-4845 [MEDIUM] CWE-264 CVE-2012-4845: The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privil The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
nvd
CVE-2007-4217P4HIGHCVSS 7.2v5.2v5.32007-11-05
CVE-2007-4217 [HIGH] CWE-119 CVE-2007-4217: Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
nvd
CVE-2009-0779P4HIGHCVSS 7.2v5.3v6.12009-03-04
CVE-2009-0779 [HIGH] CWE-119 CVE-2009-0779: Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long " Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
nvd
CVE-1999-1408P4LOWCVSS 2.1PoCv4.1v4.1.1+4 more1997-03-05
CVE-1999-1408 [LOW] CVE-1999-1408: Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
nvd
CVE-2007-0618P4HIGHCVSS 7.5v5.3.02007-01-31
CVE-2007-0618 [HIGH] CVE-2007-0618: Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has u Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
nvd
CVE-1999-0337P4HIGHCVSS 7.5v1.2.1v1.3+3 more1994-06-03
CVE-1999-0337 [HIGH] CVE-1999-0337: AIX batch queue (bsh) allows local and remote users to gain additional privileges when network print AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
nvd
CVE-2025-36244P4MEDIUMCVSS 5.5v7.2v7.32025-09-16
CVE-2025-36244 [MEDIUM] CWE-454 CVE-2025-36244: IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, cou IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
nvd
CVE-2007-5764P4HIGHCVSS 7.2v5.2v5.3+1 more2008-01-25
CVE-2007-5764 [HIGH] CWE-119 CVE-2007-5764: Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local user Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.
nvd
CVE-2007-3680P4HIGHCVSS 7.2v5.2.0v5.3.02007-07-11
CVE-2007-3680 [HIGH] CWE-119 CVE-2007-3680: Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allo Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.
nvd
CVE-2006-5003P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5003 [HIGH] CVE-2006-5003: Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to exe Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
nvd
CVE-2008-4018P4HIGHCVSS 7.2v5.2v5.3+1 more2008-09-11
CVE-2008-4018 [HIGH] CVE-2008-4018: swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to c swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.
nvd
CVE-2010-0960P4HIGHCVSS 7.2v6.1v6.1.02010-03-10
CVE-2010-0960 [HIGH] CWE-119 CVE-2010-0960: Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to ga Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2010-0961P4HIGHCVSS 7.2v6.1v6.1.02010-03-10
CVE-2010-0961 [HIGH] CWE-119 CVE-2010-0961: Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to g Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-1599P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1599 [HIGH] CWE-264 CVE-2008-1599: The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, whic The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.
nvd
CVE-2012-2200P4HIGHCVSS 7.2v6.1v7.12012-06-27
CVE-2012-2200 [HIGH] CWE-264 CVE-2012-2200: The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows l The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
nvd
Ibm Aix vulnerabilities | cvebase