cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 17 of 19
CVE-1999-1075P4MEDIUMCVSS 5.0v4.1.51998-03-18
CVE-1999-1075 [MEDIUM] CVE-1999-1075: inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
nvd
CVE-2014-0930P4MEDIUMCVSS 4.7v5.3v6.1+1 more2014-05-08
CVE-2014-0930 [MEDIUM] CVE-2014-0930: The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a d The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
nvd
CVE-2007-0392P4MEDIUMCVSS 4.6v5.32007-01-19
CVE-2007-0392 [MEDIUM] CVE-2007-0392: IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which a IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
nvd
CVE-2001-1554P4MEDIUMCVSS 5.0v4302001-12-31
CVE-2001-1554 [MEDIUM] CVE-2001-1554: IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
nvd
CVE-1999-0011P4MEDIUMCVSS 5.4v4.1v4.2+1 more1998-04-08
CVE-1999-0011 [MEDIUM] CWE-1067 CVE-1999-0011: Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
nvd
CVE-2012-0723P4MEDIUMCVSS 4.9v5.3v6.1+1 more2012-07-30
CVE-2012-0723 [MEDIUM] CWE-20 CVE-2012-0723: The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement t The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
nvd
CVE-1999-0094P4MEDIUMCVSS 4.6v4.1v4.1.1+5 more1997-10-29
CVE-1999-0094 [MEDIUM] CVE-1999-0094: AIX piodmgrsu command allows local users to gain additional group privileges. AIX piodmgrsu command allows local users to gain additional group privileges.
nvd
CVE-1999-1079P4MEDIUMCVSS 4.6v3.2.5v4.1+9 more1999-05-06
CVE-1999-1079 [MEDIUM] CVE-1999-1079: Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid pr Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
nvd
CVE-2021-29693P4MEDIUMCVSS 4.4v7.1v7.22021-06-28
CVE-2021-29693 [MEDIUM] CVE-2021-29693: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privilege IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
nvd
CVE-2021-38955P4MEDIUMCVSS 4.4v7.1v7.2+1 more2022-03-01
CVE-2021-38955 [MEDIUM] CVE-2021-38955: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a den IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.
nvd
CVE-2016-0266P4LOWCVSS 3.7v5.3v6.1+2 more2016-08-08
CVE-2016-0266 [LOW] CWE-254 CVE-2016-0266: IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-1999-0010P4MEDIUMCVSS 5.0v4.1v4.2+1 more1998-04-08
CVE-1999-0010 [MEDIUM] CVE-1999-0010: Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
nvd
CVE-2025-8732P4LOWCVSS 3.3≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2025-08-08
CVE-2025-8732 [LOW] CWE-404 CVE-2025-8732: A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnera A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vuln
nvd
CVE-1999-0019P4MEDIUMCVSS 5.0v3.2v4.11996-04-24
CVE-1999-0019 [MEDIUM] CVE-1999-0019: Delete or create a file via rpc.statd, due to invalid information. Delete or create a file via rpc.statd, due to invalid information.
nvd
CVE-1999-0087P4MEDIUMCVSS 5.0v4.1v4.2+1 more1998-02-01
CVE-1999-0087 [MEDIUM] CVE-1999-0087: Denial of service in AIX telnet can freeze a system and prevent users from accessing the server. Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
nvd
CVE-2026-0992P4LOWCVSS 2.9≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvd
CVE-2012-2192P4MEDIUMCVSS 4.9v5.3v6.1+1 more2012-06-20
CVE-2012-2192 [MEDIUM] CWE-399 CVE-2012-2192: The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
nvd
CVE-2008-1594P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-03-31
CVE-2008-1594 [MEDIUM] CVE-2008-1594: The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent v The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.
nvd
CVE-2011-0637P4MEDIUMCVSS 4.9v6.12011-01-25
CVE-2011-0637 [MEDIUM] CVE-2011-0637: The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocatin The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2001-1095P4MEDIUMCVSS 4.6v4.02001-10-09
CVE-2001-1095 [MEDIUM] CVE-2001-1095: Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r para Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.
nvd
Ibm Aix vulnerabilities | cvebase