VendorsIBMaix7.1
Vulnerabilities

IBM AIX 7.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2022-22350
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
Published 2022-03-02 · Modified
6.2EPSS 0.002
CVE-2021-38993
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.
Published 2022-02-25 · Modified
6.2EPSS 0.002
CVE-2022-43849
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43848
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43381
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-39164
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-39165
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-40233
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43380
IBM AIX denial of service
Published 2022-12-23 · Modified
6.2EPSS 0.002
CVE-2022-43382
IBM AIX denial of service
Published 2022-12-20 · Modified
6.2EPSS 0.002
CVE-2018-1655
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
Published 2018-06-22 · Modified
5.5EPSS 0.004
CVE-2016-8944
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.
Published 2017-02-15 · Modified
5.5EPSS 0.004
CVE-2012-4817
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
Published 2012-09-14 · Modified
5.0EPSS 0.076
CVE-2021-29693
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
Published 2021-06-28 · Modified
4.9EPSS 0.006
CVE-2012-2192
The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
Published 2012-06-20 · Modified
4.9EPSS 0.004
CVE-2012-0723
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
Published 2012-07-30 · Modified
4.9EPSS 0.004
CVE-2011-1375
IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
Published 2011-11-11 · Modified
4.9EPSS 0.004
CVE-2014-0930
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
Published 2014-05-08 · Modified
4.7EPSS 0.005
CVE-2021-38955
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.
Published 2022-03-01 · Modified
4.4EPSS 0.002
CVE-2014-3566
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Published 2014-10-15 · Modified
4.3EPSS 1.000
CVE-2016-0281
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
Published 2016-08-08 · Modified
4.3EPSS 0.084
CVE-2016-0266
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Published 2016-08-08 · Modified
4.3EPSS 0.014
CVE-2012-4833
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
Published 2012-10-01 · Modified
2.1EPSS 0.004
CVE-2011-3982
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
Published 2011-10-05 · Modified
2.1EPSS 0.003
← Prev2 / 2