cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 19 of 19
CVE-2005-0261P4LOWCVSS 2.1v5.2v5.32005-02-10
CVE-2005-0261 [LOW] CVE-2005-0261: lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing th lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
nvd
CVE-2004-0828P4LOWCVSS 2.1v5.2v5.32004-11-03
CVE-2004-0828 [LOW] CVE-2004-0828: The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop pri The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
nvd
CVE-1999-0129P4MEDIUMCVSS 4.6v3.2v4.1+1 more1996-12-03
CVE-1999-0129 [MEDIUM] CVE-1999-0129: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
nvd
CVE-2006-5004P4LOWCVSS 2.1v5.2.0v5.3.02006-09-27
CVE-2006-5004 [LOW] CVE-2006-5004: Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to over Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
nvd
CVE-2007-4228P4MEDIUMCVSS 4.7v4.32007-08-08
CVE-2007-4228 [MEDIUM] CVE-2007-4228: rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port lo rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.
nvd
CVE-2005-2238P4LOWCVSS 2.1v5.1v5.2+1 more2005-07-12
CVE-2005-2238 [LOW] CVE-2005-2238: ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (por ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
nvd
CVE-2001-1079P4LOWCVSS 3.6v3.2.02002-02-13
CVE-2001-1079 [LOW] CVE-2001-1079: create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with worl create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
nvd
CVE-2006-1247P4LOWCVSS 3.3v5.1v5.1l+11 more2006-04-19
CVE-2006-1247 [LOW] CWE-59 CVE-2006-1247: rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitr rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2005-1176P4LOWCVSS 1.2v5.2.0.50v5.2.0.54+2 more2005-05-02
CVE-2005-1176 [LOW] CVE-2005-1176: Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for tha Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
nvd
CVE-1999-0694P4LOWCVSS 2.1v4.2v4.31999-08-11
CVE-1999-0694 [LOW] CVE-1999-0694: Denial of service in AIX ptrace system call allows local users to crash the system. Denial of service in AIX ptrace system call allows local users to crash the system.
nvd
CVE-1999-1486P4LOWCVSS 1.2v4.1v4.1.1+7 more1998-02-25
CVE-1999-1486 [LOW] CVE-1999-1486: sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2011-3982P4LOWCVSS 2.1v6.1v7.12011-10-05
CVE-2011-3982 [LOW] CWE-399 CVE-2011-3982: The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA res The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
nvd
CVE-2005-3289P4LOWCVSS 2.1v5.2v5.32005-10-23
CVE-2005-3289 [LOW] CVE-2005-3289: LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to c LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
nvd
CVE-2010-3406P4LOWCVSS 1.7v5.32010-09-16
CVE-2010-3406 [LOW] CVE-2010-3406: Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.
nvd
CVE-2007-6680P4LOWCVSS 2.1v6.12008-01-10
CVE-2007-6680 [LOW] CVE-2007-6680: Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.
nvd
CVE-2000-0080P4LOWCVSS 2.1v4.3.22000-01-10
CVE-2000-0080 [LOW] CVE-2000-0080: AIX techlibss allows local users to overwrite files via a symlink attack. AIX techlibss allows local users to overwrite files via a symlink attack.
nvd
CVE-1999-1480P4LOWCVSS 1.2v4.31998-06-11
CVE-1999-1480 [LOW] CVE-1999-1480: (1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink atta (1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.
nvd