Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 26 of 27
CVE-2026-16890P4LOWCVSS 3.6≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16890 [LOW] CWE-190 CVE-2026-16890: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.
nvd
CVE-2026-16891P4LOWCVSS 3.3≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16891 [LOW] CWE-125 CVE-2026-16891: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
nvd
CVE-2006-0666P4MEDIUMCVSS 4.9v5.3v5.3_l2006-02-15
CVE-2006-0666 [MEDIUM] CVE-2006-0666: Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 th
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
nvd
CVE-2001-1096P4MEDIUMCVSS 4.6v4.02001-10-09
CVE-2001-1096 [MEDIUM] CVE-2001-1096: Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute co
Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.
nvd
CVE-2005-4273P4LOWCVSS 2.1v5.3v5.3_l2005-12-15
CVE-2005-4273 [LOW] CVE-2005-4273: Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local u
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
nvd
CVE-2005-0261P4LOWCVSS 2.1v5.2v5.32005-02-10
CVE-2005-0261 [LOW] CVE-2005-0261: lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing th
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
nvd
CVE-2004-0828P4LOWCVSS 2.1v5.2v5.32004-11-03
CVE-2004-0828 [LOW] CVE-2004-0828: The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop pri
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
nvd
CVE-1999-0129P4MEDIUMCVSS 4.6v3.2v4.1+1 more1996-12-03
CVE-1999-0129 [MEDIUM] CVE-1999-0129: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
nvd
CVE-2007-4228P4MEDIUMCVSS 4.7v4.32007-08-08
CVE-2007-4228 [MEDIUM] CVE-2007-4228: rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port lo
rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.
nvd
CVE-2006-5004P4LOWCVSS 2.1v5.2.0v5.3.02006-09-27
CVE-2006-5004 [LOW] CVE-2006-5004: Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to over
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
nvd
CVE-2005-2238P4LOWCVSS 2.1v5.1v5.2+1 more2005-07-12
CVE-2005-2238 [LOW] CVE-2005-2238: ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (por
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
nvd
CVE-2001-1079P4LOWCVSS 3.6v3.2.02002-02-13
CVE-2001-1079 [LOW] CVE-2001-1079: create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with worl
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
nvd
CVE-2006-1247P4LOWCVSS 3.3v5.1v5.1l+11 more2006-04-19
CVE-2006-1247 [LOW] CWE-59 CVE-2006-1247: rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitr
rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2005-1176P4LOWCVSS 1.2v5.2.0.50v5.2.0.54+2 more2005-05-02
CVE-2005-1176 [LOW] CVE-2005-1176: Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for tha
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
nvd
CVE-1999-0694P4LOWCVSS 2.1v4.2v4.31999-08-11
CVE-1999-0694 [LOW] CVE-1999-0694: Denial of service in AIX ptrace system call allows local users to crash the system.
Denial of service in AIX ptrace system call allows local users to crash the system.
nvd
CVE-1999-1486P4LOWCVSS 1.2v4.1v4.1.1+7 more1998-02-25
CVE-1999-1486 [LOW] CVE-1999-1486: sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2011-3982P4LOWCVSS 2.1v6.1v7.12011-10-05
CVE-2011-3982 [LOW] CWE-399 CVE-2011-3982: The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA res
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
nvd
CVE-2005-3289P4LOWCVSS 2.1v5.2v5.32005-10-23
CVE-2005-3289 [LOW] CVE-2005-3289: LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to c
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
nvd
CVE-2007-6680P4LOWCVSS 2.1v6.12008-01-10
CVE-2007-6680 [LOW] CVE-2007-6680: Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.
nvd
CVE-2000-0080P4LOWCVSS 2.1v4.3.22000-01-10
CVE-2000-0080 [LOW] CVE-2000-0080: AIX techlibss allows local users to overwrite files via a symlink attack.
AIX techlibss allows local users to overwrite files via a symlink attack.
nvd