Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 3 of 19
CVE-2004-0544P4HIGHCVSS 7.2PoCv4.3.3v5.1+1 more2004-08-06
CVE-2004-0544 [HIGH] CVE-2004-0544: Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
nvd
CVE-2005-2236P4HIGHCVSS 7.2PoCv5.32005-07-12
CVE-2005-2236 [HIGH] CVE-2005-2236: Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, migh
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
nvd
CVE-2007-4003P4MEDIUMCVSS 6.9PoCv5.32007-07-26
CVE-2007-4003 [MEDIUM] CVE-2007-4003: pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious lib
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.
nvd
CVE-2012-2179P4MEDIUMCVSS 6.9PoCv5.3v6.1+1 more2012-06-22
CVE-2012-2179 [MEDIUM] CWE-264 CVE-2012-2179: libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2004-1329P4HIGHCVSS 7.2PoCv5.1v5.1l+5 more2004-12-20
CVE-2004-1329 [HIGH] CVE-2004-1329: Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.
nvd
CVE-2018-1383P3CRITICALCVSS 9.1v6.1v6.1.1+17 more2018-02-13
CVE-2018-1383 [CRITICAL] CVE-2018-1383: A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
nvd
CVE-2014-3977P4MEDIUMCVSS 6.9PoCv6.1v7.12014-06-08
CVE-2014-3977 [MEDIUM] CVE-2014-3977: libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
nvd
CVE-2007-4004P4MEDIUMCVSS 6.9PoCv5.2.0v5.32007-07-26
CVE-2007-4004 [MEDIUM] CWE-119 CVE-2007-4004: Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitra
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.
nvd
CVE-2004-2312P4HIGHCVSS 7.2PoCv4.3.32004-12-31
CVE-2004-2312 [HIGH] CVE-2004-2312: Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain pri
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
nvd
CVE-2009-3517P3CRITICALCVSS 10.0v5.3.0v5.3.7+5 more2009-10-01
CVE-2009-3517 [CRITICAL] CVE-2009-3517: nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon
nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
nvd
CVE-2025-36096P3HIGHCVSS 8.1v7.2v7.32025-11-13
CVE-2025-36096 [HIGH] CWE-522 CVE-2025-36096: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in a
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
nvd
CVE-1999-0130P4HIGHCVSS 7.2PoCv4.21996-11-16
CVE-1999-0130 [HIGH] CVE-1999-0130: Local users can start Sendmail in daemon mode and gain root privileges.
Local users can start Sendmail in daemon mode and gain root privileges.
nvd
CVE-1999-0691P4HIGHCVSS 7.2PoCv4.1v4.1.1+9 more1999-09-13
CVE-1999-0691 [HIGH] CVE-1999-0691: Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
nvd
CVE-1999-1208P4HIGHCVSS 7.2PoCv3.2.5v4.1+1 more1997-07-21
CVE-1999-1208 [HIGH] CVE-1999-1208: Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
nvd
CVE-1999-0064P4HIGHCVSS 7.2PoCv3.2v3.2.4+8 more1997-05-26
CVE-1999-0064 [HIGH] CVE-1999-0064: Buffer overflow in AIX lquerylv program gives root access to local users.
Buffer overflow in AIX lquerylv program gives root access to local users.
nvd
CVE-2004-0368P3CRITICALCVSS 10.0v4.3.3v5.1+1 more2004-05-04
CVE-2004-0368 [CRITICAL] CWE-119 CVE-2004-0368: Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows re
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
nvd
CVE-2024-27260P3HIGHCVSS 8.4v7.2v7.3+1 more2024-05-16
CVE-2024-27260 [HIGH] CWE-250 CVE-2024-27260: IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulner
IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
nvd
CVE-2004-1330P4HIGHCVSS 7.2PoCv5.2v5.2.2+3 more2004-12-31
CVE-2004-1330 [HIGH] CVE-2004-1330: Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a
Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
nvd
CVE-1999-0040P4HIGHCVSS 7.2PoCv3.2v4.1+1 more1997-05-01
CVE-1999-0040 [HIGH] CVE-1999-0040: Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
nvd
CVE-1999-0122P4HIGHCVSS 7.2PoCv4.1v4.1.1+5 more1997-07-21
CVE-1999-0122 [HIGH] CVE-1999-0122: Buffer overflow in AIX lchangelv gives root access.
Buffer overflow in AIX lchangelv gives root access.
nvd