Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 3 of 27
CVE-2026-17145P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17145 [CRITICAL] CWE-269 CVE-2026-17145: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
nvd
CVE-2026-17138P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17138 [CRITICAL] CWE-121 CVE-2026-17138: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-16872P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16872 [CRITICAL] CWE-121 CVE-2026-16872: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2024-56347P3CRITICALCVSS 9.6v7.2v7.32025-03-18
CVE-2024-56347 [CRITICAL] CWE-114 CVE-2024-56347: IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to exe
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
nvd
CVE-2001-1080P3CRITICALCVSS 10.0PoCv4.3v5.12001-06-19
CVE-2001-1080 [CRITICAL] CVE-2001-1080: diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain p
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
nvd
CVE-1999-1405P3CRITICALCVSS 10.0PoCv3.2.5v4.1+6 more1999-02-17
CVE-1999-1405 [CRITICAL] CVE-1999-1405: snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
nvd
CVE-2007-3333P3MEDIUMCVSS 6.9PoCv5.2.0v5.32007-07-26
CVE-2007-3333 [MEDIUM] CWE-119 CVE-2007-3333: Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execu
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.
nvd
CVE-2026-16894P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16894 [CRITICAL] CWE-787 CVE-2026-16894: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16913P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16913 [CRITICAL] CWE-787 CVE-2026-16913: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16885P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16885 [CRITICAL] CWE-121 CVE-2026-16885: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-17157P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17157 [CRITICAL] CWE-787 CVE-2026-17157: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-1999-0042P3CRITICALCVSS 10.0PoCv4.2.11997-04-07
CVE-1999-0042 [CRITICAL] CVE-1999-0042: Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
nvd
CVE-2026-17024P2CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17024 [CRITICAL] CWE-295 CVE-2026-17024: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.
nvd
CVE-2013-4011P3HIGHCVSS 7.2PoCv6.1v7.12013-07-18
CVE-2013-4011 [HIGH] CVE-2013-4011: Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
nvd
CVE-2026-16862P3CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16862 [CRITICAL] CWE-787 CVE-2026-16862: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16864P3CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16864 [CRITICAL] CWE-787 CVE-2026-16864: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2009-2669P3HIGHCVSS 7.2PoCv5.3v6.12009-08-05
CVE-2009-2669 [HIGH] CWE-264 CVE-2009-2669: A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in
nvd
CVE-2002-1468P3CRITICALCVSS 10.0PoCv4.3.32003-04-22
CVE-2002-1468 [CRITICAL] CVE-2002-1468: Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
nvd
CVE-2026-18832P3CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-18832 [CRITICAL] CWE-787 CVE-2026-18832: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-17436P3CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17436 [CRITICAL] CWE-787 CVE-2026-17436: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd