Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 16 of 27
CVE-2008-0587P4HIGHCVSS 7.2v5.2v5.32008-02-05
CVE-2008-0587 [HIGH] CWE-119 CVE-2008-0587: Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local
Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-1600P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1600 [HIGH] CVE-2008-1600: The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, whi
The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.
nvd
CVE-2007-4794P4HIGHCVSS 7.2v5.2v5.32007-09-10
CVE-2007-4794 [HIGH] CWE-119 CVE-2007-4794: Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to
Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.
nvd
CVE-2009-2434P4HIGHCVSS 7.2v5.32009-07-13
CVE-2009-2434 [HIGH] CWE-119 CVE-2009-2434: Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges v
Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-6717P4HIGHCVSS 7.2v5.2.0v5.3.02008-09-11
CVE-2007-6717 [HIGH] CWE-119 CVE-2007-6717: Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain
Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2009-0370P4HIGHCVSS 7.2v5.2v5.2.2+9 more2009-01-30
CVE-2009-0370 [HIGH] CVE-2009-0370: Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
nvd
CVE-2020-4887P4MEDIUMCVSS 5.5v7.1v7.22021-01-20
CVE-2020-4887 [MEDIUM] CVE-2020-4887: IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore
IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any directory. IBM X-Force ID: 190911.
nvd
CVE-2026-16973P4MEDIUMCVSS 5.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16973 [MEDIUM] CWE-200 CVE-2026-16973: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.
nvd
CVE-2005-0250P4HIGHCVSS 7.2v5.1v5.2+1 more2005-05-02
CVE-2005-0250 [HIGH] CVE-2005-0250: Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execut
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.
nvd
CVE-2007-1798P4HIGHCVSS 7.2v5.2v5.32007-04-02
CVE-2007-1798 [HIGH] CVE-2007-1798: Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of
Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.
nvd
CVE-2006-1246P4HIGHCVSS 7.2v5.32006-03-17
CVE-2006-1246 [HIGH] CVE-2006-1246: Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute ar
Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.
nvd
CVE-2008-0586P4HIGHCVSS 7.2v5.2v5.32008-02-05
CVE-2008-0586 [HIGH] CWE-119 CVE-2008-0586: Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecifie
Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.
nvd
CVE-2006-2647P4HIGHCVSS 7.2v5.1v5.2+1 more2006-05-30
CVE-2006-2647 [HIGH] CVE-2006-2647: Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
nvd
CVE-2007-4791P4HIGHCVSS 7.2v5.2v5.32007-09-10
CVE-2007-4791 [HIGH] CVE-2007-4791: Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users t
Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.
nvd
CVE-2007-4354P4HIGHCVSS 7.2v5.2v5.32007-08-15
CVE-2007-4354 [HIGH] CVE-2007-4354: Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain pri
Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-1593P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1593 [HIGH] CWE-264 CVE-2008-1593: The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly prot
The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.
nvd
CVE-2007-4796P4HIGHCVSS 7.2v5.2v5.32007-09-10
CVE-2007-4796 [HIGH] CWE-119 CVE-2007-4796: Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges
Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4355P4HIGHCVSS 7.2v5.32007-08-15
CVE-2007-4355 [HIGH] CVE-2007-4355: Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecifi
Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4622P4HIGHCVSS 7.2v5.22007-11-05
CVE-2007-4622 [HIGH] CWE-189 CVE-2007-4622: Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.
Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG key) command line argument to dig.
nvd
CVE-2026-16846P4MEDIUMCVSS 6.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16846 [MEDIUM] CWE-476 CVE-2026-16846: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null pointer dereference.
nvd