cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 16 of 19
CVE-2024-52906P4MEDIUMCVSS 5.5v7.2v7.3+1 more2024-12-25
CVE-2024-52906 [MEDIUM] CWE-362 CVE-2024-52906: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerab IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
nvd
CVE-2000-0441P4MEDIUMCVSS 5.0v3.2v3.2.4+12 more2000-05-24
CVE-2000-0441 [MEDIUM] CVE-2000-0441: Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or re Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
nvd
CVE-1999-1583P4HIGHCVSS 7.2v4.31999-09-30
CVE-1999-1583 [HIGH] CVE-1999-1583: Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long host Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
nvd
CVE-2000-1222P4HIGHCVSS 7.2≤ 4.2.1.122000-12-10
CVE-2000-1222 [HIGH] CVE-2000-1222: AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which all AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
nvd
CVE-2000-0249P4HIGHCVSS 7.2v4.3v4.3.1+1 more2000-04-26
CVE-2000-0249 [HIGH] CVE-2000-0249: The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
nvd
CVE-2007-4353P4MEDIUMCVSS 6.9v5.2v5.32007-08-15
CVE-2007-4353 [MEDIUM] CVE-2007-4353: Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.
nvd
CVE-1999-0024P4MEDIUMCVSS 5.0v4.1v4.21997-08-13
CVE-1999-0024 [MEDIUM] CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs. DNS cache poisoning via BIND, by predictable query IDs.
nvd
CVE-2007-2996P4MEDIUMCVSS 6.6v5.2v5.32007-06-04
CVE-2007-2996 [MEDIUM] CVE-2007-2996: Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."
nvd
CVE-1999-0086P4MEDIUMCVSS 5.0v3.2v4.1+2 more1998-01-08
CVE-1999-0086 [MEDIUM] CVE-1999-0086: AIX routed allows remote users to modify sensitive files. AIX routed allows remote users to modify sensitive files.
nvd
CVE-2022-22350P4MEDIUMCVSS 5.5v7.1v7.2+1 more2022-03-02
CVE-2022-22350 [MEDIUM] CVE-2022-22350: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
nvd
CVE-2005-4068P4HIGHCVSS 7.2v5.1v5.2+1 more2005-12-08
CVE-2005-4068 [HIGH] CVE-2005-4068: Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
nvd
CVE-2008-2514P4MEDIUMCVSS 4.6v5.2v5.3+1 more2008-06-02
CVE-2008-2514 [MEDIUM] CWE-119 CVE-2008-2514: Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unkn Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2001-0998P4MEDIUMCVSS 5.0v4.3v4.3.3+1 more2001-09-24
CVE-2001-0998 [MEDIUM] CVE-2001-0998: IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
nvd
CVE-2003-0696P4MEDIUMCVSS 5.0v5.1v5.22004-01-20
CVE-2003-0696 [MEDIUM] CVE-2003-0696: The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
nvd
CVE-2008-1598P4MEDIUMCVSS 4.7v6.12008-03-31
CVE-2008-1598 [MEDIUM] CWE-200 CVE-2008-1598: The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memor The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.
nvd
CVE-2008-0585P4MEDIUMCVSS 6.6v5.2v5.32008-02-05
CVE-2008-0585 [MEDIUM] CWE-264 CVE-2008-0585: sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM R sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
nvd
CVE-2026-0989P4LOWCVSS 3.7≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2002-1619P4MEDIUMCVSS 5.0v4.3v4.3.1+2 more2002-03-08
CVE-2002-1619 [MEDIUM] CVE-2002-1619: Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of serv Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
nvd
CVE-2002-1201P4MEDIUMCVSS 5.0v4.3.3v52002-10-28
CVE-2002-1201 [MEDIUM] CVE-2002-1201: IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or cra IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
nvd
CVE-1999-0628P4MEDIUMCVSS 5.0v4.21997-07-01
CVE-1999-0628 [MEDIUM] CVE-1999-0628: The rwho/rwhod service is running, which exposes machine status and user information. The rwho/rwhod service is running, which exposes machine status and user information.
nvd
Ibm Aix vulnerabilities | cvebase