cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 23 of 27
CVE-2000-0441P4MEDIUMCVSS 5.0v3.2v3.2.4+12 more2000-05-24
CVE-2000-0441 [MEDIUM] CVE-2000-0441: Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or re Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
nvd
CVE-1999-1583P4HIGHCVSS 7.2v4.31999-09-30
CVE-1999-1583 [HIGH] CVE-1999-1583: Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long host Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
nvd
CVE-2004-0545P4HIGHCVSS 7.2v5.1v5.22004-08-06
CVE-2004-0545 [HIGH] CVE-2004-0545: LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack. LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2000-1222P4HIGHCVSS 7.2≤ 4.2.1.122000-12-10
CVE-2000-1222 [HIGH] CVE-2000-1222: AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which all AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.
nvd
CVE-2000-0249P4HIGHCVSS 7.2v4.3v4.3.1+1 more2000-04-26
CVE-2000-0249 [HIGH] CVE-2000-0249: The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
nvd
CVE-2007-4353P4MEDIUMCVSS 6.9v5.2v5.32007-08-15
CVE-2007-4353 [MEDIUM] CVE-2007-4353: Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.
nvd
CVE-1999-0024P4MEDIUMCVSS 5.0v4.1v4.21997-08-13
CVE-1999-0024 [MEDIUM] CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs. DNS cache poisoning via BIND, by predictable query IDs.
nvd
CVE-1999-0086P4MEDIUMCVSS 5.0v3.2v4.1+2 more1998-01-08
CVE-1999-0086 [MEDIUM] CVE-1999-0086: AIX routed allows remote users to modify sensitive files. AIX routed allows remote users to modify sensitive files.
nvd
CVE-2022-22350P4MEDIUMCVSS 5.5v7.1v7.2+1 more2022-03-02
CVE-2022-22350 [MEDIUM] CVE-2022-22350: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
nvd
CVE-2005-4068P4HIGHCVSS 7.2v5.1v5.2+1 more2005-12-08
CVE-2005-4068 [HIGH] CVE-2005-4068: Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
nvd
CVE-2008-2514P4MEDIUMCVSS 4.6v5.2v5.3+1 more2008-06-02
CVE-2008-2514 [MEDIUM] CWE-119 CVE-2008-2514: Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unkn Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2026-16849P4MEDIUMCVSS 4.3≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16849 [MEDIUM] CWE-129 CVE-2026-16849: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary.
nvd
CVE-2007-2996P4MEDIUMCVSS 6.6v5.2v5.32007-06-04
CVE-2007-2996 [MEDIUM] CVE-2007-2996: Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl."
nvd
CVE-2026-0989P4LOWCVSS 3.7≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2001-0998P4MEDIUMCVSS 5.0v4.3v4.3.3+1 more2001-09-24
CVE-2001-0998 [MEDIUM] CVE-2001-0998: IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
nvd
CVE-2003-0696P4MEDIUMCVSS 5.0v5.1v5.22004-01-20
CVE-2003-0696 [MEDIUM] CVE-2003-0696: The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
nvd
CVE-2008-1598P4MEDIUMCVSS 4.7v6.12008-03-31
CVE-2008-1598 [MEDIUM] CWE-200 CVE-2008-1598: The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memor The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.
nvd
CVE-2026-16897P4MEDIUMCVSS 4.4≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16897 [MEDIUM] CWE-369 CVE-2026-16897: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.
nvd
CVE-2008-0585P4MEDIUMCVSS 6.6v5.2v5.32008-02-05
CVE-2008-0585 [MEDIUM] CWE-264 CVE-2008-0585: sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM R sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
nvd
CVE-2026-16888P4LOWCVSS 3.7≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16888 [LOW] CWE-22 CVE-2026-16888: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.
nvd
Ibm Aix vulnerabilities | cvebase