cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 18 of 19
CVE-2006-5007P4MEDIUMCVSS 4.6v5.2.0v5.3.02006-09-27
CVE-2006-5007 [MEDIUM] CVE-2006-5007: Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local u Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
nvd
CVE-2006-0667P4MEDIUMCVSS 4.6v5.2v5.32006-03-10
CVE-2006-0667 [MEDIUM] CVE-2006-0667: lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack. lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
nvd
CVE-1999-0078P4LOWCVSS 1.9v3.2v4.1+1 more1996-04-18
CVE-1999-0078 [LOW] CVE-1999-0078: pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
nvd
CVE-2022-43382P4MEDIUMCVSS 4.4v7.1v7.2+2 more2022-12-20
CVE-2022-43382 [MEDIUM] CWE-399 CVE-2022-43382: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vu IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.
nvd
CVE-2007-4798P4MEDIUMCVSS 6.6v5.2v5.32007-09-10
CVE-2007-4798 [MEDIUM] CWE-264 CVE-2007-4798: Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allo Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
nvd
CVE-2008-0589P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-02-05
CVE-2008-0589 [MEDIUM] CWE-200 CVE-2008-0589: The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitiv The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-1375P4MEDIUMCVSS 4.9v6.1v7.12011-11-11
CVE-2011-1375 [MEDIUM] CWE-264 CVE-2011-1375: IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, wh IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
nvd
CVE-2008-1595P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-03-31
CVE-2008-1595 [MEDIUM] CWE-264 CVE-2008-1595: The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permiss The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.
nvd
CVE-2001-0573P4MEDIUMCVSS 4.6v42001-08-02
CVE-2001-0573 [MEDIUM] CVE-2001-0573: lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.
nvd
CVE-2008-0509P4MEDIUMCVSS 4.4v4.32008-01-31
CVE-2008-0509 [MEDIUM] CWE-119 CVE-2008-0509: Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.
nvd
CVE-1999-0345P4MEDIUMCVSS 5.0v3.2v4.1+1 more1997-01-01
CVE-1999-0345 [MEDIUM] CVE-1999-0345: Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
nvd
CVE-2008-1597P4MEDIUMCVSS 4.9v6.12008-03-31
CVE-2008-1597 [MEDIUM] CVE-2008-1597: The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denia The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."
nvd
CVE-2007-4799P4MEDIUMCVSS 4.9v5.32007-09-10
CVE-2007-4799 [MEDIUM] CWE-264 CVE-2007-4799: The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when proces The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.
nvd
CVE-2007-2995P4MEDIUMCVSS 4.3v5.2.0v5.32007-06-04
CVE-2007-2995 [MEDIUM] CVE-2007-2995: Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and atta Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.
nvd
CVE-2006-0674P4MEDIUMCVSS 4.6v5.2v5.2.2+3 more2006-02-13
CVE-2006-0674 [MEDIUM] CVE-2006-0674: Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users t Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.
nvd
CVE-2012-4833P4LOWCVSS 2.1v6.1v7.12012-10-01
CVE-2012-4833 [LOW] CWE-264 CVE-2012-4833: fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
nvd
CVE-2006-6915P4MEDIUMCVSS 4.0v5.2.0v5.3.02006-12-31
CVE-2006-6915 [MEDIUM] CVE-2006-6915: ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
nvd
CVE-2006-0666P4MEDIUMCVSS 4.9v5.3v5.3_l2006-02-15
CVE-2006-0666 [MEDIUM] CVE-2006-0666: Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 th Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
nvd
CVE-2001-1096P4MEDIUMCVSS 4.6v4.02001-10-09
CVE-2001-1096 [MEDIUM] CVE-2001-1096: Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute co Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.
nvd
CVE-2005-4273P4LOWCVSS 2.1v5.3v5.3_l2005-12-15
CVE-2005-4273 [LOW] CVE-2005-4273: Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local u Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
nvd
Ibm Aix vulnerabilities | cvebase