cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 5 of 19
CVE-2025-62230P3HIGHCVSS 7.3≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvd
CVE-2013-3005P3HIGHCVSS 8.5v6.1v7.12013-07-06
CVE-2013-3005 [HIGH] CWE-264 CVE-2013-3005: The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows r The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
nvd
CVE-2001-1440P3CRITICALCVSS 10.0v5.1l2001-12-21
CVE-2001-1440 [CRITICAL] CVE-2001-1440: Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remo Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
nvd
CVE-1999-0092P4HIGHCVSS 7.2PoCv4.2.11997-10-29
CVE-1999-0092 [HIGH] CVE-1999-0092: Various vulnerabilities in the AIX portmir command allows local users to obtain root access. Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
nvd
CVE-1999-0048P3CRITICALCVSS 10.0v3.1v4.1+1 more1997-01-27
CVE-1999-0048 [CRITICAL] CVE-1999-0048: Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privi Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
nvd
CVE-2005-1037P3CRITICALCVSS 10.0v5.3.02005-05-02
CVE-2005-1037 [CRITICAL] CVE-2005-1037: Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gai Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.
nvd
CVE-2022-41290P3HIGHCVSS 8.4v7.1v7.2+2 more2022-12-23
CVE-2022-41290 [HIGH] CWE-250 CVE-2022-41290: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.
nvd
CVE-2023-26286P3HIGHCVSS 7.8v7.1v7.2+2 more2023-04-26
CVE-2023-26286 [HIGH] CVE-2023-26286: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.
nvd
CVE-1999-0014P4HIGHCVSS 7.2PoCv4.1v4.2+1 more1998-01-21
CVE-1999-0014 [HIGH] CVE-1999-0014: Unauthorized privileged access or denial of service via dtappgather program in CDE. Unauthorized privileged access or denial of service via dtappgather program in CDE.
nvd
CVE-2005-2232P4MEDIUMCVSS 4.6PoCv5.1v5.2+1 more2005-07-12
CVE-2005-2232 [MEDIUM] CVE-2005-2232: Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitr Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v4.3.3v5.1+1 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-2024-47115P3HIGHCVSS 7.8v7.2v7.3+1 more2024-12-07
CVE-2024-47115 [HIGH] CWE-78 CVE-2024-47115: IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
nvd
CVE-1999-0112P4HIGHCVSS 7.2PoCv4.1v4.21997-05-01
CVE-1999-0112 [HIGH] CVE-1999-0112: Buffer overflow in AIX dtterm program for the CDE. Buffer overflow in AIX dtterm program for the CDE.
nvd
CVE-2020-4829P3HIGHCVSS 7.8v7.1v7.22020-12-10
CVE-2020-4829 [HIGH] CVE-2020-4829: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user c IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.
nvd
CVE-2021-29801P3HIGHCVSS 7.8v7.1v7.22021-08-26
CVE-2021-29801 [HIGH] CVE-2021-29801: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.
nvd
CVE-2021-29741P3HIGHCVSS 7.8v7.1v7.22021-08-02
CVE-2021-29741 [HIGH] CVE-2021-29741: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ks IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.
nvd
CVE-2023-45166P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45166 [HIGH] CVE-2023-45166: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.
nvd
CVE-2022-36768P3HIGHCVSS 7.8v7.1v7.2+1 more2022-09-13
CVE-2022-36768 [HIGH] CVE-2022-36768: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.
nvd
CVE-2022-34356P3HIGHCVSS 7.8v7.1v7.2+1 more2022-09-13
CVE-2022-34356 [HIGH] CVE-2022-34356: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.
nvd
CVE-1999-0116P4MEDIUMCVSS 5.0PoCv3.2.5v4.1+1 more1996-09-19
CVE-1999-0116 [MEDIUM] CVE-1999-0116: Denial of service when an attacker sends many SYN packets to create multiple connections without eve Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.
nvd
Ibm Aix vulnerabilities | cvebase