VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-2004-0544
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
Published 2004-06-10 · Modified
7.22 PoCEPSS 0.012
CVE-1999-0014
Unauthorized privileged access or denial of service via dtappgather program in CDE.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.012
CVE-1999-0122
Buffer overflow in AIX lchangelv gives root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.011
CVE-2005-2236
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
Published 2005-07-12 · Modified
7.21 PoCEPSS 0.011
CVE-2005-0262
Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.
Published 2005-02-10 · Modified
7.21 PoCEPSS 0.011
CVE-2005-0263
Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
Published 2005-02-10 · Modified
7.21 PoCEPSS 0.011
CVE-2004-2312
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
Published 2005-08-16 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0130
Local users can start Sendmail in daemon mode and gain root privileges.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0693
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.010
CVE-2000-1121
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.010
CVE-2000-1120
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
Published 2001-01-22 · Modified
7.21 PoCEPSS 0.010
CVE-2014-8904
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
Published 2015-01-15 · Modified
7.21 PoCEPSS 0.010
CVE-2004-1054
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Published 2004-12-22 · Modified
7.22 PoCEPSS 0.010
CVE-1999-1121
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.009
CVE-2000-1124
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0112
Buffer overflow in AIX dtterm program for the CDE.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0092
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0023
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-1208
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0064
Buffer overflow in AIX lquerylv program gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.007
CVE-2009-2669
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.
Published 2009-08-05 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0118
AIX infod allows local users to gain root access through an X display.
Published 2000-06-02 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0115
AIX bugfiler program allows local users to gain root access.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0138
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
Published 1999-09-29 · Modified
7.2EPSS 0.007
CVE-1999-1583
Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
Published 2005-04-21 · Modified
7.2EPSS 0.006
CVE-1999-0033
Command execution in Sun systems via buffer overflow in the at program.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-2014-3074
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
Published 2014-07-02 · Modified
7.2EPSS 0.006
CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-2025-14915
IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability
Published 2026-03-25 · Analyzed
7.2EPSS 0.006
CVE-2005-0250
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.
Published 2005-02-08 · Modified
7.2EPSS 0.005
CVE-2005-3060
Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.
Published 2005-09-30 · Modified
7.2EPSS 0.005
CVE-2007-5764
Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.
Published 2008-01-25 · Modified
7.2EPSS 0.005
CVE-2007-4623
Stack-based buffer overflow in the sendrmt function in bellmail in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via a long parameter to the m command.
Published 2007-11-05 · Modified
7.2EPSS 0.005
CVE-2005-2234
Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
Published 2005-07-12 · Modified
7.2EPSS 0.005
CVE-2005-2235
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
Published 2005-07-12 · Modified
7.2EPSS 0.005
CVE-2005-2233
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.
Published 2005-07-12 · Modified
7.2EPSS 0.005
CVE-2005-4271
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
Published 2005-12-15 · Modified
7.2EPSS 0.005
← Prev11 / 25Next →