cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 19 of 27
CVE-2008-1710P4HIGHCVSS 7.2v6.12008-04-09
CVE-2008-1710 [HIGH] CWE-264 CVE-2008-1710: Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.
nvd
CVE-2026-16866P4MEDIUMCVSS 4.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16866 [MEDIUM] CWE-125 CVE-2026-16866: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
nvd
CVE-2013-5419P4MEDIUMCVSS 6.9v6.1v7.12013-10-04
CVE-2013-5419 [MEDIUM] CWE-119 CVE-2013-5419: Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 a Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.
nvd
CVE-2007-4236P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4236 [MEDIUM] CVE-2007-4236: Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group p Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.
nvd
CVE-2007-4237P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4237 [MEDIUM] CVE-2007-4237: Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows loc Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.
nvd
CVE-2008-5384P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5384 [MEDIUM] CWE-264 CVE-2008-5384: crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cro crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.
nvd
CVE-2010-3405P4MEDIUMCVSS 6.8v5.3v6.12010-09-16
CVE-2010-3405 [MEDIUM] CWE-119 CVE-2010-3405: Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.
nvd
CVE-2008-5387P4MEDIUMCVSS 6.2v6.1v6.1.1+1 more2008-12-09
CVE-2008-5387 [MEDIUM] CWE-119 CVE-2008-5387: Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabl Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.
nvd
CVE-1999-0903P4HIGHCVSS 7.5v4.3.21999-10-26
CVE-1999-0903 [HIGH] CVE-1999-0903: genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports gre genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
nvd
CVE-2004-1028P4HIGHCVSS 7.2v5.1v5.1l+5 more2005-01-10
CVE-2004-1028 [HIGH] CVE-2004-1028: Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local user Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.
nvd
CVE-2000-1123P4HIGHCVSS 7.2v4.3v4.3.1+2 more2001-01-09
CVE-2000-1123 [HIGH] CVE-2000-1123: Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbi Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
nvd
CVE-1999-0072P4HIGHCVSS 7.2v4.1v4.1.1+6 more1997-10-22
CVE-1999-0072 [HIGH] CVE-1999-0072: Buffer overflow in AIX xdat gives root access to local users. Buffer overflow in AIX xdat gives root access to local users.
nvd
CVE-2001-0533P4HIGHCVSS 7.2v4.3v5.12001-08-14
CVE-2001-0533 [HIGH] CVE-2001-0533: Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileg Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.
nvd
CVE-1999-0117P4HIGHCVSS 7.2v3.1v3.21992-03-31
CVE-1999-0117 [HIGH] CVE-1999-0117: AIX passwd allows local users to gain root access. AIX passwd allows local users to gain root access.
nvd
CVE-2005-0240P4HIGHCVSS 7.2v5.22005-05-02
CVE-2005-0240 [HIGH] CVE-2005-0240: Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.
nvd
CVE-2009-4362P4HIGHCVSS 7.2v6.12009-12-21
CVE-2009-4362 [HIGH] CWE-119 CVE-2009-4362: Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (a Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via long string arguments. NOTE: some of these details are obtained from third party information.
nvd
CVE-2016-0281P4LOWCVSS 3.7v5.3v6.1+2 more2016-08-08
CVE-2016-0281 [LOW] CWE-20 CVE-2016-0281: The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
nvd
CVE-2008-5386P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5386 [MEDIUM] CWE-119 CVE-2008-5386: Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows loca Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2007-4238P4MEDIUMCVSS 6.9v5.2v5.32007-08-08
CVE-2007-4238 [MEDIUM] CVE-2007-4238: AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
nvd
CVE-2006-6914P4MEDIUMCVSS 5.0v5.2.0v5.3.02006-12-31
CVE-2006-6914 [MEDIUM] CVE-2006-6914: Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensi Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.
nvd
Ibm Aix vulnerabilities | cvebase