Ibm Aix vulnerabilities
377 known vulnerabilities affecting ibm/aix.
Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29
Vulnerabilities
Page 6 of 19
CVE-2004-2697P4MEDIUMCVSS 6.9PoCv4.3.3v5.1+1 more2004-12-31
CVE-2004-2697 [MEDIUM] CWE-362 CVE-2004-2697: The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
nvd
CVE-2022-22351P3HIGHCVSS 8.6≥ 7.1.5.0, ≤ 7.1.5.37≥ 7.2.4.0, ≤ 7.2.4.4+8 more2022-03-07
CVE-2022-22351 [HIGH] CVE-2022-22351: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vuln
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396
nvd
CVE-2017-1093P3HIGHCVSS 7.8v6.1v7.1+1 more2017-02-02
CVE-2017-1093 [HIGH] CVE-2017-1093: IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.
nvd
CVE-2021-38990P3HIGHCVSS 7.8v7.1v7.22022-01-10
CVE-2021-38990 [HIGH] CVE-2021-38990: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.
nvd
CVE-2021-38991P3HIGHCVSS 7.8v7.0v7.1+2 more2022-01-11
CVE-2021-38991 [HIGH] CVE-2021-38991: IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili
IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.
nvd
CVE-2024-27273P3HIGHCVSS 7.8v7.2v7.3+1 more2024-05-07
CVE-2024-27273 [HIGH] CWE-266 CVE-2024-27273: IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could po
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.
nvd
CVE-2001-0671P3CRITICALCVSS 10.0v4.3v5.12001-12-06
CVE-2001-0671 [CRITICAL] CVE-2001-0671: Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 all
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
nvd
CVE-2005-0156P4LOWCVSS 2.1PoCv5.2v5.32005-02-07
CVE-2005-0156 [LOW] CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sper
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
nvd
CVE-2017-1541P3HIGHCVSS 7.3v5.3v6.1+2 more2017-10-04
CVE-2017-1541 [HIGH] CWE-20 CVE-2017-1541: A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.se
A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from being updated correctly. IBM X-Force ID: 130809.
nvd
CVE-2000-1119P4MEDIUMCVSS 4.6PoCv4.2v4.2.1+4 more2001-01-09
CVE-2000-1119 [MEDIUM] CVE-2000-1119: Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitr
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
nvd
CVE-1999-0099P3CRITICALCVSS 10.0v3.2v4.11995-10-19
CVE-1999-0099 [CRITICAL] CVE-1999-0099: Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
nvd
CVE-2003-0170P3CRITICALCVSS 10.0v5.22004-03-29
CVE-2003-0170 [CRITICAL] CVE-2003-0170: Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication,
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
nvd
CVE-2003-0784P3CRITICALCVSS 10.0v4.3.3v5.1+1 more2003-10-06
CVE-2003-0784 [CRITICAL] CVE-2003-0784: Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attacke
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
nvd
CVE-2017-1692P3HIGHCVSS 7.8v5.3v6.1+2 more2018-02-07
CVE-2017-1692 [HIGH] CVE-2017-1692: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally auth
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.
nvd
CVE-2023-45170P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45170 [HIGH] CVE-2023-45170: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.
nvd
CVE-2023-45174P3HIGHCVSS 7.8v7.2v7.3+1 more2023-12-13
CVE-2023-45174 [HIGH] CVE-2023-45174: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the
IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.
nvd
CVE-2016-6038P3MEDIUMCVSS 6.5v5.3v6.1+1 more2016-09-26
CVE-2016-6038 [MEDIUM] CWE-22 CVE-2016-6038: Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI)
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a crafted URL.
nvd
CVE-1999-0088P4CRITICALCVSS 10.0v4.31998-10-26
CVE-1999-0088 [CRITICAL] CVE-1999-0088: IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
nvd
CVE-2002-0677P3HIGHCVSS 7.5v4.3.3v5.12002-07-23
CVE-2002-0677 [HIGH] CVE-2002-0677: CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory loca
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
nvd
CVE-1999-0097P4CRITICALCVSS 10.0v3.2v3.2.4+9 more1997-10-29
CVE-1999-0097 [CRITICAL] CVE-1999-0097: The AIX FTP client can be forced to execute commands from a malicious server through shell metachara
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
nvd