cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 18 of 27
CVE-2006-5006P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5006 [HIGH] CVE-2006-5006: Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code vi Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.
nvd
CVE-2003-0954P4HIGHCVSS 7.2v4.3.3v5.1+1 more2003-12-31
CVE-2003-0954 [HIGH] CVE-2003-0954: Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges. Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
nvd
CVE-2002-1548P4HIGHCVSS 7.2v4.3.02003-03-31
CVE-2002-1548 [HIGH] CVE-2002-1548: Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execut Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
nvd
CVE-2003-0257P4HIGHCVSS 7.2v4.3v4.3.1+4 more2004-04-15
CVE-2003-0257 [HIGH] CVE-2003-0257: Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local user Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
nvd
CVE-2009-3516P4HIGHCVSS 7.2v5.3.0v5.3.7+5 more2009-10-01
CVE-2009-3516 [HIGH] CWE-255 CVE-2009-3516: gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerbe gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
nvd
CVE-1999-1487P4HIGHCVSS 7.2v4.1v4.1.1+7 more1998-01-21
CVE-1999-1487 [HIGH] CVE-1999-1487: Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or mo Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
nvd
CVE-2008-2515P4HIGHCVSS 7.2v5.2v5.3+1 more2008-06-02
CVE-2008-2515 [HIGH] CWE-264 CVE-2008-2515: Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileg Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."
nvd
CVE-1999-1574P4HIGHCVSS 7.5v4.3.01998-07-06
CVE-1999-1574 [HIGH] CVE-1999-1574: Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
nvd
CVE-2002-0746P4CRITICALCVSS 10.0v4.3.32002-08-12
CVE-2002-0746 [CRITICAL] CVE-2002-0746: Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
nvd
CVE-2002-0743P4CRITICALCVSS 10.0v4.3.32002-08-12
CVE-2002-0743 [CRITICAL] CVE-2002-0743: mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buff mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
nvd
CVE-2002-1690P4CRITICALCVSS 10.0v3.2.52002-12-31
CVE-2002-1690 [CRITICAL] CVE-2002-1690: Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "securit Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
nvd
CVE-2004-0243P4MEDIUMCVSS 5.0≥ 4.3.3, ≤ 5.12004-11-23
CVE-2004-0243 [MEDIUM] CWE-203 CVE-2004-0243: AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
nvd
CVE-1999-1121P4HIGHCVSS 7.2≤ 3.21992-03-19
CVE-1999-1121 [HIGH] CVE-1999-1121: The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges. The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
nvd
CVE-1999-0627P4UNKNOWNCVSS 0.0v3.1v3.21992-03-01
CVE-1999-0627 [NONE] CVE-1999-0627: The rexd service is running, which uses weak authentication that can allow an attacker to execute co The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
nvd
CVE-1999-0318P4HIGHCVSS 7.2v41997-03-01
CVE-1999-0318 [HIGH] CVE-1999-0318: Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
nvd
CVE-2000-0466P4HIGHCVSS 7.2v4.3v4.3.1+1 more2000-06-20
CVE-2000-0466 [HIGH] CVE-2000-0466: AIX cdmount allows local users to gain root privileges via shell metacharacters. AIX cdmount allows local users to gain root privileges via shell metacharacters.
nvd
CVE-2006-4416P4HIGHCVSS 7.2v5.1v5.2+1 more2006-08-28
CVE-2006-4416 [HIGH] CVE-2006-4416: Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.
nvd
CVE-2008-1596P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1596 [HIGH] CVE-2008-1596: Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.
nvd
CVE-1999-1552P4HIGHCVSS 7.2≤ 3.2.5v3.1+2 more1994-07-20
CVE-1999-1552 [HIGH] CVE-1999-1552: dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check pri dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
nvd
CVE-2003-1018P4HIGHCVSS 7.2v4.3.3v5.1+1 more2004-03-29
CVE-2003-1018 [HIGH] CVE-2003-1018: Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq gr Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.
nvd
Ibm Aix vulnerabilities | cvebase