Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 16 of 19
CVE-2024-52906P4MEDIUMCVSS 5.5v7.2v7.3+1 more2024-12-25
CVE-2024-52906 [MEDIUM] CWE-362 CVE-2024-52906: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerab
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1
could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
nvd
CVE-2000-0441P4MEDIUMCVSS 5.0v3.2v3.2.4+12 more2000-05-24
CVE-2000-0441 [MEDIUM] CVE-2000-0441: Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or re
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
nvd
CVE-1999-1583P4HIGHCVSS 7.2v4.31999-09-30
CVE-1999-1583 [HIGH] CVE-1999-1583: Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long host
Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
nvd
CVE-2000-1222P4HIGHCVSS 7.2≤ 4.2.1.122000-12-10
CVE-2000-1222 [HIGH] CVE-2000-1222: AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which all
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
nvd
CVE-2000-0249P4HIGHCVSS 7.2v4.3v4.3.1+1 more2000-04-26
CVE-2000-0249 [HIGH] CVE-2000-0249: The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
nvd
CVE-2007-4353P4MEDIUMCVSS 6.9v5.2v5.32007-08-15
CVE-2007-4353 [MEDIUM] CVE-2007-4353: Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root
Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.
nvd
CVE-1999-0024P4MEDIUMCVSS 5.0v4.1v4.21997-08-13
CVE-1999-0024 [MEDIUM] CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs.
DNS cache poisoning via BIND, by predictable query IDs.
nvd
CVE-2007-2996P4MEDIUMCVSS 6.6v5.2v5.32007-06-04
CVE-2007-2996 [MEDIUM] CVE-2007-2996: Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."
nvd
CVE-1999-0086P4MEDIUMCVSS 5.0v3.2v4.1+2 more1998-01-08
CVE-1999-0086 [MEDIUM] CVE-1999-0086: AIX routed allows remote users to modify sensitive files.
AIX routed allows remote users to modify sensitive files.
nvd
CVE-2022-22350P4MEDIUMCVSS 5.5v7.1v7.2+1 more2022-03-02
CVE-2022-22350 [MEDIUM] CVE-2022-22350: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
nvd
CVE-2005-4068P4HIGHCVSS 7.2v5.1v5.2+1 more2005-12-08
CVE-2005-4068 [HIGH] CVE-2005-4068: Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
nvd
CVE-2008-2514P4MEDIUMCVSS 4.6v5.2v5.3+1 more2008-06-02
CVE-2008-2514 [MEDIUM] CWE-119 CVE-2008-2514: Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unkn
Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2001-0998P4MEDIUMCVSS 5.0v4.3v4.3.3+1 more2001-09-24
CVE-2001-0998 [MEDIUM] CVE-2001-0998: IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
nvd
CVE-2003-0696P4MEDIUMCVSS 5.0v5.1v5.22004-01-20
CVE-2003-0696 [MEDIUM] CVE-2003-0696: The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
nvd
CVE-2008-1598P4MEDIUMCVSS 4.7v6.12008-03-31
CVE-2008-1598 [MEDIUM] CWE-200 CVE-2008-1598: The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memor
The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.
nvd
CVE-2008-0585P4MEDIUMCVSS 6.6v5.2v5.32008-02-05
CVE-2008-0585 [MEDIUM] CWE-264 CVE-2008-0585: sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM R
sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
nvd
CVE-2026-0989P4LOWCVSS 3.7≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2002-1619P4MEDIUMCVSS 5.0v4.3v4.3.1+2 more2002-03-08
CVE-2002-1619 [MEDIUM] CVE-2002-1619: Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of serv
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
nvd
CVE-2002-1201P4MEDIUMCVSS 5.0v4.3.3v52002-10-28
CVE-2002-1201 [MEDIUM] CVE-2002-1201: IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or cra
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
nvd
CVE-1999-0628P4MEDIUMCVSS 5.0v4.21997-07-01
CVE-1999-0628 [MEDIUM] CVE-1999-0628: The rwho/rwhod service is running, which exposes machine status and user information.
The rwho/rwhod service is running, which exposes machine status and user information.
nvd