Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 24 of 27
CVE-2002-1619P4MEDIUMCVSS 5.0v4.3v4.3.1+2 more2002-03-08
CVE-2002-1619 [MEDIUM] CVE-2002-1619: Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of serv
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
nvd
CVE-2002-1201P4MEDIUMCVSS 5.0v4.3.3v52002-10-28
CVE-2002-1201 [MEDIUM] CVE-2002-1201: IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or cra
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
nvd
CVE-1999-0628P4MEDIUMCVSS 5.0v4.21997-07-01
CVE-1999-0628 [MEDIUM] CVE-1999-0628: The rwho/rwhod service is running, which exposes machine status and user information.
The rwho/rwhod service is running, which exposes machine status and user information.
nvd
CVE-1999-1075P4MEDIUMCVSS 5.0v4.1.51998-03-18
CVE-1999-1075 [MEDIUM] CVE-1999-1075: inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
nvd
CVE-2014-0930P4MEDIUMCVSS 4.7v5.3v6.1+1 more2014-05-08
CVE-2014-0930 [MEDIUM] CVE-2014-0930: The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a d
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
nvd
CVE-2001-1554P4MEDIUMCVSS 5.0v4302001-12-31
CVE-2001-1554 [MEDIUM] CVE-2001-1554: IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
nvd
CVE-1999-0011P4MEDIUMCVSS 5.4v4.1v4.2+1 more1998-04-08
CVE-1999-0011 [MEDIUM] CWE-1067 CVE-1999-0011: Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
nvd
CVE-2012-0723P4MEDIUMCVSS 4.9v5.3v6.1+1 more2012-07-30
CVE-2012-0723 [MEDIUM] CWE-20 CVE-2012-0723: The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement t
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
nvd
CVE-1999-0094P4MEDIUMCVSS 4.6v4.1v4.1.1+5 more1997-10-29
CVE-1999-0094 [MEDIUM] CVE-1999-0094: AIX piodmgrsu command allows local users to gain additional group privileges.
AIX piodmgrsu command allows local users to gain additional group privileges.
nvd
CVE-2007-0392P4MEDIUMCVSS 4.6v5.32007-01-19
CVE-2007-0392 [MEDIUM] CVE-2007-0392: IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which a
IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
nvd
CVE-1999-1079P4MEDIUMCVSS 4.6v3.2.5v4.1+9 more1999-05-06
CVE-1999-1079 [MEDIUM] CVE-1999-1079: Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid pr
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
nvd
CVE-2021-29693P4MEDIUMCVSS 4.4v7.1v7.22021-06-28
CVE-2021-29693 [MEDIUM] CVE-2021-29693: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privilege
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
nvd
CVE-2021-38955P4MEDIUMCVSS 4.4v7.1v7.2+1 more2022-03-01
CVE-2021-38955 [MEDIUM] CVE-2021-38955: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a den
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.
nvd
CVE-2022-43382P4MEDIUMCVSS 4.4v7.1v7.2+2 more2022-12-20
CVE-2022-43382 [MEDIUM] CWE-399 CVE-2022-43382: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vu
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.
nvd
CVE-2016-0266P4LOWCVSS 3.7v5.3v6.1+2 more2016-08-08
CVE-2016-0266 [LOW] CWE-254 CVE-2016-0266: IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-1999-0010P4MEDIUMCVSS 5.0v4.1v4.2+1 more1998-04-08
CVE-1999-0010 [MEDIUM] CVE-1999-0010: Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
nvd
CVE-2025-8732P4LOWCVSS 3.3≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2025-08-08
CVE-2025-8732 [LOW] CWE-404 CVE-2025-8732: A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnera
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vuln
nvd
CVE-1999-0019P4MEDIUMCVSS 5.0v3.2v4.11996-04-24
CVE-1999-0019 [MEDIUM] CVE-1999-0019: Delete or create a file via rpc.statd, due to invalid information.
Delete or create a file via rpc.statd, due to invalid information.
nvd
CVE-1999-0087P4MEDIUMCVSS 5.0v4.1v4.2+1 more1998-02-01
CVE-1999-0087 [MEDIUM] CVE-1999-0087: Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
nvd
CVE-2026-0992P4LOWCVSS 2.9≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvd