VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2005-1037
Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.
Published 2005-04-10 · Modified
10.0EPSS 0.024
CVE-2007-3794
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
Published 2007-07-15 · Modified
10.0EPSS 0.022
CVE-2004-2388
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
Published 2005-08-16 · Modified
10.0EPSS 0.021
CVE-2002-1689
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
Published 2005-06-21 · Modified
10.0EPSS 0.021
CVE-2003-0784
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
Published 2003-09-23 · Modified
10.0EPSS 0.021
CVE-2001-1061
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
Published 2002-02-02 · Modified
10.0EPSS 0.018
CVE-2002-0746
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
Published 2002-07-26 · Modified
10.0EPSS 0.018
CVE-2002-0745
Buffer overflow in uucp in AIX 4.3.3.
Published 2002-07-26 · Modified
10.0EPSS 0.015
CVE-2002-0744
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
Published 2002-07-26 · Modified
10.0EPSS 0.015
CVE-2002-0743
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
Published 2002-07-26 · Modified
10.0EPSS 0.015
CVE-2002-0742
Buffer overflow in pioout on AIX 4.3.3.
Published 2002-07-26 · Modified
10.0EPSS 0.015
CVE-1999-0835
Denial of service in BIND named via malformed SIG records.
Published 2000-01-04 · Modified
10.0EPSS 0.015
CVE-2002-1690
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
Published 2005-06-21 · Modified
10.0EPSS 0.014
CVE-2002-1686
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
Published 2005-06-21 · Modified
10.0EPSS 0.014
CVE-2024-56346
IBM AIX command execution
Published 2025-03-18 · Analyzed
10.0EPSS 0.011
CVE-2025-36250
AIX Code Execution
Published 2025-11-13 · Analyzed
10.0EPSS 0.007
CVE-2026-15068
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.9EPSS 0.011
CVE-2026-16816
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.9EPSS 0.008
CVE-2026-18835
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.9EPSS 0.008
CVE-2025-36038
IBM WebSphere Application Server code execution
Published 2025-06-25 · Analyzed
9.8EPSS 0.108
CVE-2018-20732
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
Published 2019-01-17 · Modified
9.8EPSS 0.040
CVE-2020-4693
IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.
Published 2020-09-02 · Modified
9.8EPSS 0.025
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Published 2022-11-16 · Modified
9.8EPSS 0.018
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.
Published 2022-06-30 · Modified
9.8EPSS 0.015
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.
Published 2022-06-17 · Modified
9.8EPSS 0.011
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2026-17142
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.009
CVE-2026-16882
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.009
CVE-2026-8855
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.8EPSS 0.008
CVE-2026-17122
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-16913
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-17157
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-16894
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-16885
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
CVE-2026-17040
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
9.8EPSS 0.008
CVE-2026-16872
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
9.8EPSS 0.008
← Prev2 / 25Next →