Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 20 of 27
CVE-2003-0914P4MEDIUMCVSS 4.3v5.1l2003-12-15
CVE-2003-0914 [MEDIUM] CVE-2003-0914: ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
nvd
CVE-2026-16829P4MEDIUMCVSS 5.3≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16829 [MEDIUM] CWE-476 CVE-2026-16829: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
nvd
CVE-2009-0536P4MEDIUMCVSS 4.9v5.2.0v5.3.0+6 more2009-02-11
CVE-2009-0536 [MEDIUM] CWE-264 CVE-2009-0536: at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
nvd
CVE-2000-1216P4HIGHCVSS 7.2v4.3.02000-01-27
CVE-2000-1216 [HIGH] CWE-120 CVE-2000-1216: Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root priv
Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.
nvd
CVE-1999-0089P4HIGHCVSS 7.2v4.31997-10-28
CVE-1999-0089 [HIGH] CVE-1999-0089: Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
nvd
CVE-2009-4361P4HIGHCVSS 7.2v6.12009-12-21
CVE-2009-4361 [HIGH] CWE-119 CVE-2009-4361: Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (
Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via a long string argument. NOTE: some of these details are obtained from third party information.
nvd
CVE-2007-0670P4MEDIUMCVSS 4.6v5.2v5.32007-02-03
CVE-2007-0670 [MEDIUM] CWE-119 CVE-2007-0670: Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code
Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.
nvd
CVE-2015-4948P4MEDIUMCVSS 6.9v5.3v6.1+1 more2015-10-16
CVE-2015-4948 [MEDIUM] CWE-264 CVE-2015-4948: netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows lo
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-5385P4MEDIUMCVSS 6.9v6.1v6.1.1+1 more2008-12-09
CVE-2008-5385 [MEDIUM] CWE-264 CVE-2008-5385: enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfi
enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.
nvd
CVE-2007-5804P4MEDIUMCVSS 6.9v5.2v5.32007-11-05
CVE-2007-5804 [MEDIUM] CVE-2007-5804: cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons,
cfgcon in IBM AIX 5.2 and 5.3 does not properly validate the argument to the "-p" option to swcons, which allows local users in the system group to create or overwrite an arbitrary file, and enable world writability of this file, by using the file's name as the argument.
nvd
CVE-2003-0285P4MEDIUMCVSS 5.0≤ 5.22003-06-16
CVE-2003-0285 [MEDIUM] CVE-2003-0285: IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) pr
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.
nvd
CVE-2022-40233P4MEDIUMCVSS 6.2v7.1v7.2+2 more2022-12-23
CVE-2022-40233 [MEDIUM] CWE-20 CVE-2022-40233: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 235599.
nvd
CVE-2022-39164P4MEDIUMCVSS 6.2v7.1v7.2+2 more2022-12-23
CVE-2022-39164 [MEDIUM] CWE-400 CVE-2022-39164: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerabilit
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.
nvd
CVE-2026-16855P4MEDIUMCVSS 5.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16855 [MEDIUM] CWE-787 CVE-2026-16855: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap buffer overflow.
nvd
CVE-1999-0131P4HIGHCVSS 7.2v3.2v4.1+1 more1996-09-11
CVE-1999-0131 [HIGH] CVE-1999-0131: Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root a
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
nvd
CVE-1999-1013P4HIGHCVSS 7.2v4.1.5v4.2.11999-09-23
CVE-1999-1013 [HIGH] CVE-1999-1013: named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to ga
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
nvd
CVE-2000-1122P4HIGHCVSS 7.2v4.2v4.2.1+4 more2001-01-09
CVE-2000-1122 [HIGH] CVE-2000-1122: Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute ar
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.
nvd
CVE-2001-1329P4HIGHCVSS 7.2v4.2.02001-06-11
CVE-2001-1329 [HIGH] CVE-2001-1329: Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long comma
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
nvd
CVE-2001-1330P4HIGHCVSS 7.2v4.2.02001-06-11
CVE-2001-1330 [HIGH] CVE-2001-1330: Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long comma
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
nvd
CVE-1999-0091P4HIGHCVSS 7.2v4.1v4.1.1+6 more1997-10-28
CVE-1999-0091 [HIGH] CVE-1999-0091: Buffer overflow in AIX writesrv command allows local users to obtain root access.
Buffer overflow in AIX writesrv command allows local users to obtain root access.
nvd