Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 2 of 27
CVE-2016-8972P3HIGHCVSS 7.8PoCv6.1v7.1+1 more2017-02-15
CVE-2016-8972 [HIGH] CWE-264 CVE-2016-8972: IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
nvd
CVE-2026-16882P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16882 [CRITICAL] CWE-78 CVE-2026-16882: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-1999-0208P3CRITICALCVSS 10.0PoCv3.2v4.11995-12-12
CVE-1999-0208 [CRITICAL] CVE-1999-0208: rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
nvd
CVE-2000-0844P3CRITICALCVSS 10.0PoCv3.2v3.2.4+13 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2016-6079P3HIGHCVSS 7.8PoCv5.3v6.1+2 more2017-02-15
CVE-2016-6079 [HIGH] CWE-264 CVE-2016-6079: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally auth
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
nvd
CVE-2026-16919P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16919 [CRITICAL] CWE-843 CVE-2026-16919: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
nvd
CVE-2026-16656P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16656 [CRITICAL] CWE-287 CVE-2026-16656: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
nvd
CVE-2026-17000P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17000 [CRITICAL] CWE-287 CVE-2026-17000: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
nvd
CVE-2006-4254P3HIGHCVSS 7.5PoCv5.1v5.2+1 more2006-08-21
CVE-2006-4254 [HIGH] CVE-2006-4254: Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain pri
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.
nvd
CVE-1999-0128P4MEDIUMCVSS 5.0PoCv3.2v4.1+1 more1996-12-18
CVE-1999-0128 [MEDIUM] CVE-1999-0128: Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
nvd
CVE-1999-0101P3CRITICALCVSS 10.0PoCv3.2v4.1+1 more1996-12-10
CVE-1999-0101 [CRITICAL] CVE-1999-0101: Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt D
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
nvd
CVE-2026-18824P2HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-18824 [HIGH] CWE-78 CVE-2026-18824: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-16840P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16840 [CRITICAL] CWE-787 CVE-2026-16840: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2025-36236P2CRITICALCVSS 9.1v7.2v7.32025-11-13
CVE-2025-36236 [CRITICAL] CWE-22 CVE-2025-36236: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
nvd
CVE-2025-36250P2CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36250 [CRITICAL] CVE-2025-36250: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
nvd
CVE-2026-17118P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17118 [CRITICAL] CWE-416 CVE-2026-17118: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
nvd
CVE-1999-0513P4MEDIUMCVSS 5.0PoCv3.1v3.2+2 more1998-01-05
CVE-1999-0513 [MEDIUM] CVE-1999-0513: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denia
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
nvd
CVE-2026-17136P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17136 [CRITICAL] CWE-134 CVE-2026-17136: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
nvd
CVE-2026-17122P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17122 [CRITICAL] CWE-787 CVE-2026-17122: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2025-36251P3CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36251 [CRITICAL] CVE-2025-36251: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a r
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
nvd