Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 15 of 27
CVE-2026-17007P4HIGHCVSS 7.1≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17007 [HIGH] CWE-125 CVE-2026-17007: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
nvd
CVE-2002-1622P4HIGHCVSS 7.5v4.32002-12-31
CVE-2002-1622 [HIGH] CVE-2002-1622: Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
nvd
CVE-2004-2388P4CRITICALCVSS 10.0v4.3.32004-12-31
CVE-2004-2388 [CRITICAL] CVE-2004-2388: rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam,
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
nvd
CVE-2009-1954P4HIGHCVSS 7.8v5.32009-06-08
CVE-2009-1954 [HIGH] CVE-2009-1954: Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a den
Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.
nvd
CVE-2012-0194P4HIGHCVSS 7.1v5.3v6.1+1 more2012-02-06
CVE-2012-0194 [HIGH] CVE-2012-0194: The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled,
The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.
nvd
CVE-2012-4817P4MEDIUMCVSS 5.0v5.3v6.1+1 more2012-09-14
CVE-2012-4817 [MEDIUM] CVE-2012-4817: The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, d
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2001-1557P4HIGHCVSS 7.5v4.3v5.12001-12-31
CVE-2001-1557 [HIGH] CVE-2001-1557: Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
nvd
CVE-2008-2513P4HIGHCVSS 7.2v5.2v5.3+1 more2008-06-02
CVE-2008-2513 [HIGH] CWE-119 CVE-2008-2513: Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary c
Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.
nvd
CVE-2006-5005P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5005 [HIGH] CVE-2006-5005: Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to exe
Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.
nvd
CVE-2012-0745P4HIGHCVSS 7.2v5.3v6.1+1 more2012-05-04
CVE-2012-0745 [HIGH] CWE-264 CVE-2012-0745: The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not proper
The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4621P4HIGHCVSS 7.2v5.22007-11-05
CVE-2007-4621 [HIGH] CWE-119 CVE-2007-4621: Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command lin
Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.
nvd
CVE-2007-4795P4HIGHCVSS 7.2v5.2v5.32007-09-10
CVE-2007-4795 [HIGH] CWE-119 CVE-2007-4795: Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privi
Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.
nvd
CVE-2007-0978P4HIGHCVSS 7.2v5.32007-02-16
CVE-2007-0978 [HIGH] CVE-2007-0978: Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
nvd
CVE-2021-29706P4HIGHCVSS 7.1v7.1.0v7.12021-06-17
CVE-2021-29706 [HIGH] CVE-2021-29706: IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility
IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.
nvd
CVE-2003-0119P4HIGHCVSS 7.5v4.3.3v5.1+1 more2004-02-03
CVE-2003-0119 [HIGH] CVE-2003-0119: The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
nvd
CVE-2010-1124P4HIGHCVSS 7.8v5.3v5.3.02010-03-26
CVE-2010-1124 [HIGH] CVE-2010-1124: bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after
bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addre
nvd
CVE-2006-5009P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5009 [HIGH] CVE-2006-5009: Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrar
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.
nvd
CVE-2006-4522P4HIGHCVSS 7.2v5.2v5.32006-09-01
CVE-2006-4522 [HIGH] CVE-2006-4522: Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary c
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
nvd
CVE-2006-5011P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5011 [HIGH] CVE-2006-5011: Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execu
Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".
nvd
CVE-2008-0588P4HIGHCVSS 7.2v5.2v5.32008-02-05
CVE-2008-0588 [HIGH] CWE-264 CVE-2008-0588: Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local u
Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
nvd