cbcvebase.

Ibm Aix vulnerabilities

522 known vulnerabilities affecting ibm/aix.

Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32

Vulnerabilities

Page 6 of 27
CVE-2026-16996P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16996 [HIGH] CWE-787 CVE-2026-16996: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow.
nvd
CVE-2026-19446P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-19446 [HIGH] CWE-400 CVE-2026-19446: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
nvd
CVE-2018-1383P3CRITICALCVSS 9.1v6.1v6.1.1+17 more2018-02-13
CVE-2018-1383 [CRITICAL] CVE-2018-1383: A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
nvd
CVE-2014-3977P4MEDIUMCVSS 6.9PoCv6.1v7.12014-06-08
CVE-2014-3977 [MEDIUM] CVE-2014-3977: libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
nvd
CVE-2007-4004P4MEDIUMCVSS 6.9PoCv5.2.0v5.32007-07-26
CVE-2007-4004 [MEDIUM] CWE-119 CVE-2007-4004: Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitra Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.
nvd
CVE-2026-16847P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16847 [HIGH] CWE-787 CVE-2026-16847: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-16834P3CRITICALCVSS 9.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16834 [CRITICAL] CWE-190 CVE-2026-16834: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
nvd
CVE-2004-2312P4HIGHCVSS 7.2PoCv4.3.32004-12-31
CVE-2004-2312 [HIGH] CVE-2004-2312: Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain pri Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
nvd
CVE-2026-16814P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16814 [HIGH] CWE-787 CVE-2026-16814: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-16875P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16875 [HIGH] CWE-78 CVE-2026-16875: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.
nvd
CVE-2009-3517P3CRITICALCVSS 10.0v5.3.0v5.3.7+5 more2009-10-01
CVE-2009-3517 [CRITICAL] CVE-2009-3517: nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.
nvd
CVE-2026-19449P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-19449 [HIGH] CWE-269 CVE-2026-19449: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
nvd
CVE-2026-15061P3HIGHCVSS 8.2≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-15061 [HIGH] CWE-22 CVE-2026-15061: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
nvd
CVE-1999-0130P4HIGHCVSS 7.2PoCv4.21996-11-16
CVE-1999-0130 [HIGH] CVE-1999-0130: Local users can start Sendmail in daemon mode and gain root privileges. Local users can start Sendmail in daemon mode and gain root privileges.
nvd
CVE-1999-0691P4HIGHCVSS 7.2PoCv4.1v4.1.1+9 more1999-09-13
CVE-1999-0691 [HIGH] CVE-1999-0691: Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
nvd
CVE-1999-1208P4HIGHCVSS 7.2PoCv3.2.5v4.1+1 more1997-07-21
CVE-1999-1208 [HIGH] CVE-1999-1208: Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
nvd
CVE-1999-0064P4HIGHCVSS 7.2PoCv3.2v3.2.4+8 more1997-05-26
CVE-1999-0064 [HIGH] CVE-1999-0064: Buffer overflow in AIX lquerylv program gives root access to local users. Buffer overflow in AIX lquerylv program gives root access to local users.
nvd
CVE-2004-0368P3CRITICALCVSS 10.0v4.3.3v5.1+1 more2004-05-04
CVE-2004-0368 [CRITICAL] CWE-119 CVE-2004-0368: Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows re Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
nvd
CVE-2026-18670P3CRITICALCVSS 9.1≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-18670 [CRITICAL] CWE-190 CVE-2026-18670: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
nvd
CVE-2026-19442P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-19442 [HIGH] CWE-822 CVE-2026-19442: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
nvd
Ibm Aix vulnerabilities | cvebase