Ibm Aix vulnerabilities
522 known vulnerabilities affecting ibm/aix.
Total CVEs
522
CISA KEV
0
Public exploits
72
Exploited in wild
5
Severity breakdown
CRITICAL90HIGH257MEDIUM142LOW32
Vulnerabilities
Page 9 of 27
CVE-2026-17124P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-17124 [HIGH] CWE-125 CVE-2026-17124: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.
nvd
CVE-2026-18842P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-18842 [HIGH] CWE-787 CVE-2026-18842: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write.
nvd
CVE-2026-16946P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16946 [HIGH] CWE-787 CVE-2026-16946: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buffer overflow.
nvd
CVE-2011-1561P3MEDIUMCVSS 6.8v6.12011-04-05
CVE-2011-1561 [MEDIUM] CWE-287 CVE-2011-1561: The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap
The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.
nvd
CVE-2026-14970P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-14970 [HIGH] CWE-120 CVE-2026-14970: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registrat
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.
nvd
CVE-2025-62230P3HIGHCVSS 7.3≥ 7.2.5, < 7.2.5.12≥ 7.3.2, < 7.3.3.3+1 more2025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvd
CVE-2013-3005P3HIGHCVSS 8.5v6.1v7.12013-07-06
CVE-2013-3005 [HIGH] CWE-264 CVE-2013-3005: The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows r
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
nvd
CVE-2001-1440P3CRITICALCVSS 10.0v5.1l2001-12-21
CVE-2001-1440 [CRITICAL] CVE-2001-1440: Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remo
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
nvd
CVE-1999-0092P4HIGHCVSS 7.2PoCv4.2.11997-10-29
CVE-1999-0092 [HIGH] CVE-1999-0092: Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
nvd
CVE-1999-0048P3CRITICALCVSS 10.0v3.1v4.1+1 more1997-01-27
CVE-1999-0048 [CRITICAL] CVE-1999-0048: Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privi
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
nvd
CVE-2022-41290P3HIGHCVSS 8.4v7.1v7.2+2 more2022-12-23
CVE-2022-41290 [HIGH] CWE-250 CVE-2022-41290: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.
nvd
CVE-2023-26286P3HIGHCVSS 7.8v7.1v7.2+2 more2023-04-26
CVE-2023-26286 [HIGH] CVE-2023-26286: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.
nvd
CVE-2026-16989P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16989 [HIGH] CWE-59 CVE-2026-16989: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
nvd
CVE-2026-16943P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16943 [HIGH] CWE-787 CVE-2026-16943: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-16991P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16991 [HIGH] CWE-269 CVE-2026-16991: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
nvd
CVE-2026-16821P3HIGHCVSS 7.8≥ 7.2.5.0, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-28
CVE-2026-16821 [HIGH] CWE-134 CVE-2026-16821: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
nvd
CVE-2026-16703P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-19
CVE-2026-16703 [HIGH] CWE-269 CVE-2026-16703: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2026-16937P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16937 [HIGH] CWE-269 CVE-2026-16937: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2026-16923P3HIGHCVSS 7.8≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-16923 [HIGH] CWE-269 CVE-2026-16923: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
nvd
CVE-2026-18828P3HIGHCVSS 7.5≥ 7.2.5, ≤ 7.2.5.212≥ 7.3.2, ≤ 7.3.2.5+4 more2026-08-20
CVE-2026-18828 [HIGH] CWE-787 CVE-2026-18828: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
nvd