cbcvebase.

Ibm Aix vulnerabilities

377 known vulnerabilities affecting ibm/aix.

Total CVEs
377
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL47HIGH180MEDIUM120LOW29

Vulnerabilities

Page 8 of 19
CVE-2007-4217P4HIGHCVSS 7.2v5.2v5.32007-11-05
CVE-2007-4217 [HIGH] CWE-119 CVE-2007-4217: Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
nvd
CVE-2009-0779P4HIGHCVSS 7.2v5.3v6.12009-03-04
CVE-2009-0779 [HIGH] CWE-119 CVE-2009-0779: Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long " Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
nvd
CVE-1999-1408P4LOWCVSS 2.1PoCv4.1v4.1.1+4 more1997-03-05
CVE-1999-1408 [LOW] CVE-1999-1408: Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
nvd
CVE-2013-3035P4HIGHCVSS 7.1v6.1v7.12013-06-21
CVE-2013-3035 [HIGH] CWE-20 CVE-2013-3035: The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
nvd
CVE-1999-0337P4HIGHCVSS 7.5v1.2.1v1.3+3 more1994-06-03
CVE-1999-0337 [HIGH] CVE-1999-0337: AIX batch queue (bsh) allows local and remote users to gain additional privileges when network print AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
nvd
CVE-2007-0618P4HIGHCVSS 7.5v5.3.02007-01-31
CVE-2007-0618 [HIGH] CVE-2007-0618: Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has u Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
nvd
CVE-2012-4845P4MEDIUMCVSS 6.8v6.1v7.12012-10-20
CVE-2012-4845 [MEDIUM] CWE-264 CVE-2012-4845: The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privil The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
nvd
CVE-2007-5764P4HIGHCVSS 7.2v5.2v5.3+1 more2008-01-25
CVE-2007-5764 [HIGH] CWE-119 CVE-2007-5764: Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local user Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.
nvd
CVE-2007-3680P4HIGHCVSS 7.2v5.2.0v5.3.02007-07-11
CVE-2007-3680 [HIGH] CWE-119 CVE-2007-3680: Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allo Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.
nvd
CVE-2006-5003P4HIGHCVSS 7.2v5.2.0v5.3.02006-09-27
CVE-2006-5003 [HIGH] CVE-2006-5003: Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to exe Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
nvd
CVE-2008-4018P4HIGHCVSS 7.2v5.2v5.3+1 more2008-09-11
CVE-2008-4018 [HIGH] CVE-2008-4018: swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to c swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establish weak permissions and root ownership for this file, via unspecified vectors. NOTE: this can be leveraged to gain privileges. NOTE: this issue exists because of an incomplete fix for CVE-2007-5805.
nvd
CVE-2010-0960P4HIGHCVSS 7.2v6.1v6.1.02010-03-10
CVE-2010-0960 [HIGH] CWE-119 CVE-2010-0960: Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to ga Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2010-0961P4HIGHCVSS 7.2v6.1v6.1.02010-03-10
CVE-2010-0961 [HIGH] CWE-119 CVE-2010-0961: Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to g Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2008-1599P4HIGHCVSS 7.2v5.2v5.3+1 more2008-03-31
CVE-2008-1599 [HIGH] CWE-264 CVE-2008-1599: The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, whic The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.
nvd
CVE-2012-2200P4HIGHCVSS 7.2v6.1v7.12012-06-27
CVE-2012-2200 [HIGH] CWE-264 CVE-2012-2200: The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows l The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
nvd
CVE-2002-1622P4HIGHCVSS 7.5v4.32002-12-31
CVE-2002-1622 [HIGH] CVE-2002-1622: Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
nvd
CVE-2004-2388P4CRITICALCVSS 10.0v4.3.32004-12-31
CVE-2004-2388 [CRITICAL] CVE-2004-2388: rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
nvd
CVE-2009-1954P4HIGHCVSS 7.8v5.32009-06-08
CVE-2009-1954 [HIGH] CVE-2009-1954: Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a den Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.
nvd
CVE-2012-4817P4MEDIUMCVSS 5.0v5.3v6.1+1 more2012-09-14
CVE-2012-4817 [MEDIUM] CVE-2012-4817: The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, d The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2001-1557P4HIGHCVSS 7.5v4.3v5.12001-12-31
CVE-2001-1557 [HIGH] CVE-2001-1557: Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges. Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
nvd
Ibm Aix vulnerabilities | cvebase