Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 2 of 19
CVE-2006-4254P3HIGHCVSS 7.5PoCv5.1v5.2+1 more2006-08-21
CVE-2006-4254 [HIGH] CVE-2006-4254: Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain pri
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.
nvd
CVE-1999-0128P4MEDIUMCVSS 5.0PoCv3.2v4.1+1 more1996-12-18
CVE-1999-0128 [MEDIUM] CVE-1999-0128: Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
nvd
CVE-1999-0101P3CRITICALCVSS 10.0PoCv3.2v4.1+1 more1996-12-10
CVE-1999-0101 [CRITICAL] CVE-1999-0101: Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt D
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
nvd
CVE-2025-36236P2CRITICALCVSS 9.1v7.2v7.32025-11-13
CVE-2025-36236 [CRITICAL] CWE-22 CVE-2025-36236: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
nvd
CVE-2025-36250P2CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36250 [CRITICAL] CVE-2025-36250: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
nvd
CVE-1999-0513P4MEDIUMCVSS 5.0PoCv3.1v3.2+2 more1998-01-05
CVE-1999-0513 [MEDIUM] CVE-1999-0513: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denia
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
nvd
CVE-2025-36251P3CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36251 [CRITICAL] CVE-2025-36251: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a r
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
nvd
CVE-2024-56347P3CRITICALCVSS 9.6v7.2v7.32025-03-18
CVE-2024-56347 [CRITICAL] CWE-114 CVE-2024-56347: IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to exe
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
nvd
CVE-2001-1080P3CRITICALCVSS 10.0PoCv4.3v5.12001-06-19
CVE-2001-1080 [CRITICAL] CVE-2001-1080: diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain p
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
nvd
CVE-1999-1405P3CRITICALCVSS 10.0PoCv3.2.5v4.1+6 more1999-02-17
CVE-1999-1405 [CRITICAL] CVE-1999-1405: snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
nvd
CVE-1999-0042P3CRITICALCVSS 10.0PoCv4.2.11997-04-07
CVE-1999-0042 [CRITICAL] CVE-1999-0042: Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
nvd
CVE-2013-4011P3HIGHCVSS 7.2PoCv6.1v7.12013-07-18
CVE-2013-4011 [HIGH] CVE-2013-4011: Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
nvd
CVE-2007-3333P3MEDIUMCVSS 6.9PoCv5.2.0v5.32007-07-26
CVE-2007-3333 [MEDIUM] CWE-119 CVE-2007-3333: Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execu
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.
nvd
CVE-2009-2669P3HIGHCVSS 7.2PoCv5.3v6.12009-08-05
CVE-2009-2669 [HIGH] CWE-264 CVE-2009-2669: A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in
nvd
CVE-2002-1468P3CRITICALCVSS 10.0PoCv4.3.32003-04-22
CVE-2002-1468 [CRITICAL] CVE-2002-1468: Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
nvd
CVE-2014-8904P3HIGHCVSS 7.2PoCv5.3v6.1+1 more2015-01-15
CVE-2014-8904 [HIGH] CWE-264 CVE-2014-8904: lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
nvd
CVE-1999-0745P3CRITICALCVSS 10.0PoCv2.2.1v3.1+3 more1999-08-18
CVE-1999-0745 [CRITICAL] CVE-1999-0745: Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
nvd
CVE-2014-3074P3HIGHCVSS 7.2PoCv6.1v7.12014-07-02
CVE-2014-3074 [HIGH] CWE-264 CVE-2014-3074: The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 roo
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
nvd
CVE-1999-0041P4HIGHCVSS 7.5PoCv3.2.5v4.1+1 more1997-02-13
CVE-1999-0041 [HIGH] CVE-1999-0041: Buffer overflow in NLS (Natural Language Service).
Buffer overflow in NLS (Natural Language Service).
nvd
CVE-2002-0679P3CRITICALCVSS 10.0v4.3.3v5.12002-09-05
CVE-2002-0679 [CRITICAL] CVE-2002-0679: Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) a
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
nvd