cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 25 of 27
CVE-2012-2192P4MEDIUMCVSS 4.9v5.3v6.1+1 more2012-06-20
CVE-2012-2192 [MEDIUM] CWE-399 CVE-2012-2192: The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
nvd
CVE-2008-1594P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-03-31
CVE-2008-1594 [MEDIUM] CVE-2008-1594: The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent v The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.
nvd
CVE-2011-0637P4MEDIUMCVSS 4.9v6.12011-01-25
CVE-2011-0637 [MEDIUM] CVE-2011-0637: The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocatin The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2001-1095P4MEDIUMCVSS 4.6v4.02001-10-09
CVE-2001-1095 [MEDIUM] CVE-2001-1095: Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r para Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.
nvd
CVE-2006-0667P4MEDIUMCVSS 4.6v5.2v5.32006-03-10
CVE-2006-0667 [MEDIUM] CVE-2006-0667: lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack. lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
nvd
CVE-1999-0078P4LOWCVSS 1.9v3.2v4.1+1 more1996-04-18
CVE-1999-0078 [LOW] CVE-1999-0078: pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
nvd
CVE-2007-4798P4MEDIUMCVSS 6.6v5.2v5.32007-09-10
CVE-2007-4798 [MEDIUM] CWE-264 CVE-2007-4798: Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allo Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
nvd
CVE-2008-0589P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-02-05
CVE-2008-0589 [MEDIUM] CWE-200 CVE-2008-0589: The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitiv The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-1375P4MEDIUMCVSS 4.9v6.1v7.12011-11-11
CVE-2011-1375 [MEDIUM] CWE-264 CVE-2011-1375: IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, wh IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
nvd
CVE-2008-1595P4MEDIUMCVSS 4.9v5.2v5.3+1 more2008-03-31
CVE-2008-1595 [MEDIUM] CWE-264 CVE-2008-1595: The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permiss The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.
nvd
CVE-2007-4799P4MEDIUMCVSS 4.9v5.32007-09-10
CVE-2007-4799 [MEDIUM] CWE-264 CVE-2007-4799: The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when proces The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.
nvd
CVE-2001-0573P4MEDIUMCVSS 4.6v42001-08-02
CVE-2001-0573 [MEDIUM] CVE-2001-0573: lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.
nvd
CVE-2006-5007P4MEDIUMCVSS 4.6v5.2.0v5.3.02006-09-27
CVE-2006-5007 [MEDIUM] CVE-2006-5007: Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local u Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
nvd
CVE-2008-0509P4MEDIUMCVSS 4.4v4.32008-01-31
CVE-2008-0509 [MEDIUM] CWE-119 CVE-2008-0509: Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.
nvd
CVE-1999-0345P4MEDIUMCVSS 5.0v3.2v4.1+1 more1997-01-01
CVE-1999-0345 [MEDIUM] CVE-1999-0345: Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
nvd
CVE-2008-1597P4MEDIUMCVSS 4.9v6.12008-03-31
CVE-2008-1597 [MEDIUM] CVE-2008-1597: The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denia The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."
nvd
CVE-2007-2995P4MEDIUMCVSS 4.3v5.2.0v5.32007-06-04
CVE-2007-2995 [MEDIUM] CVE-2007-2995: Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and atta Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.
nvd
CVE-2006-0674P4MEDIUMCVSS 4.6v5.2v5.2.2+3 more2006-02-13
CVE-2006-0674 [MEDIUM] CVE-2006-0674: Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users t Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.
nvd
CVE-2012-4833P4LOWCVSS 2.1v6.1v7.12012-10-01
CVE-2012-4833 [LOW] CWE-264 CVE-2012-4833: fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
nvd
CVE-2006-6915P4MEDIUMCVSS 4.0v5.2.0v5.3.02006-12-31
CVE-2006-6915 [MEDIUM] CVE-2006-6915: ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.
nvd
Ibm Aix vulnerabilities | cvebase