Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 7 of 27
CVE-2024-27260P3HIGHCVSS 8.4v7.2v7.3+1 more2024-05-16
CVE-2024-27260 [HIGH] CWE-250 CVE-2024-27260: IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulner
IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
nvd
CVE-2025-36096P3HIGHCVSS 8.1v7.2v7.32025-11-13
CVE-2025-36096 [HIGH] CWE-522 CVE-2025-36096: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in a
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
nvd
CVE-2004-1330P4HIGHCVSS 7.2PoCv5.2v5.2.2+3 more2004-12-31
CVE-2004-1330 [HIGH] CVE-2004-1330: Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a
Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
nvd
CVE-1999-0040P4HIGHCVSS 7.2PoCv3.2v4.1+1 more1997-05-01
CVE-1999-0040 [HIGH] CVE-1999-0040: Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
nvd
CVE-1999-0122P4HIGHCVSS 7.2PoCv4.1v4.1.1+5 more1997-07-21
CVE-1999-0122 [HIGH] CVE-1999-0122: Buffer overflow in AIX lchangelv gives root access.
Buffer overflow in AIX lchangelv gives root access.
nvd
CVE-1999-0693P4HIGHCVSS 7.2PoCv42000-03-02
CVE-1999-0693 [HIGH] CVE-1999-0693: Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
nvd
CVE-2004-1054P4HIGHCVSS 7.2PoCv5.1v5.1l+5 more2005-01-10
CVE-2004-1054 [HIGH] CVE-2004-1054: Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local u
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
nvd
CVE-2000-1124P4HIGHCVSS 7.2PoCv4.3v4.3.1+2 more2001-01-09
CVE-2000-1124 [HIGH] CVE-2000-1124: Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long env
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
nvd
CVE-1999-0023P4HIGHCVSS 7.2PoCv3.2v4.1+1 more1996-07-24
CVE-1999-0023 [HIGH] CVE-1999-0023: Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
nvd
CVE-1999-0118P4HIGHCVSS 7.2PoCv3.2v4.1+2 more1998-11-01
CVE-1999-0118 [HIGH] CVE-1999-0118: AIX infod allows local users to gain root access through an X display.
AIX infod allows local users to gain root access through an X display.
nvd
CVE-2026-17060P3CRITICALCVSS 9.1≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17060 [CRITICAL] CWE-200 CVE-2026-17060: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.
nvd
CVE-2009-1786P4MEDIUMCVSS 6.9PoCv5.3v6.12009-05-26
CVE-2009-1786 [MEDIUM] CWE-362 CVE-2009-1786: The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitr
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.
nvd
CVE-2026-17422P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17422 [HIGH] CWE-787 CVE-2026-17422: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-16936P3HIGHCVSS 8.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16936 [HIGH] CWE-787 CVE-2026-16936: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2005-4272P3CRITICALCVSS 10.0v5.1v5.1l+5 more2005-12-15
CVE-2005-4272 [CRITICAL] CVE-2005-4272: Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary c
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
nvd
CVE-1999-0038P4HIGHCVSS 8.4PoCv3.2v4.1+1 more1997-04-26
CVE-1999-0038 [HIGH] CWE-120 CVE-1999-0038: Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in xlock program allows local users to execute commands as root.
nvd
CVE-2024-25021P3HIGHCVSS 8.4v7.3v7.3, VIOS 4.12024-02-22
CVE-2024-25021 [HIGH] CWE-114 CVE-2024-25021: IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vul
IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.
nvd
CVE-2026-16997P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16997 [HIGH] CWE-269 CVE-2026-16997: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management.
nvd
CVE-2026-16944P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16944 [HIGH] CWE-787 CVE-2026-16944: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-16945P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16945 [HIGH] CWE-121 CVE-2026-16945: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd