VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2002-1201
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
Published 2002-10-15 · Modified
5.0EPSS 0.021
CVE-2010-2090
The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.
Published 2010-05-27 · Modified
5.0EPSS 0.017
CVE-2004-0243
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
Published 2004-03-18 · Modified
5.0EPSS 0.017
CVE-2009-0435
Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.
Published 2009-02-10 · Modified
5.0EPSS 0.017
CVE-1999-0019
Delete or create a file via rpc.statd, due to invalid information.
Published 1999-09-29 · Modified
5.0EPSS 0.017
CVE-2006-6914
Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.
Published 2007-01-10 · Modified
5.0EPSS 0.015
CVE-1999-0628
The rwho/rwhod service is running, which exposes machine status and user information.
Published 1999-09-29 · Modified
5.0EPSS 0.015
CVE-1999-0111
RIP v1 is susceptible to spoofing.
Published 1999-09-29 · Modified
5.0EPSS 0.014
CVE-1999-0087
Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.
Published 1999-09-29 · Modified
5.0EPSS 0.014
CVE-1999-0566
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
Published 1999-09-29 · Modified
5.0EPSS 0.013
CVE-1999-0345
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
Published 2000-02-04 · Modified
5.0EPSS 0.013
CVE-2003-0696
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
Published 2004-01-08 · Modified
5.0EPSS 0.013
CVE-1999-1075
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
Published 2001-09-12 · Modified
5.0EPSS 0.013
CVE-2001-1554
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
Published 2005-07-14 · Modified
5.0EPSS 0.012
CVE-2007-1223
Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending "data unexpectedly through the port".
Published 2007-03-02 · Modified
5.0EPSS 0.012
CVE-2002-1040
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
Published 2002-08-31 · Modified
5.0EPSS 0.011
CVE-2002-1041
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
Published 2002-08-31 · Modified
5.0EPSS 0.011
CVE-2008-7288
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
Published 2011-04-21 · Modified
5.0EPSS 0.011
CVE-2000-0441
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
Published 2000-07-12 · Modified
5.0EPSS 0.009
CVE-2023-42031
IBM CICS TX denial of service
Published 2023-10-24 · Modified
4.9EPSS 0.010
CVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160.
Published 2021-08-30 · Modified
4.9EPSS 0.010
CVE-2021-29693
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
Published 2021-06-28 · Modified
4.9EPSS 0.006
CVE-2009-0536
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.
Published 2009-02-11 · Modified
4.9EPSS 0.005
CVE-2012-2192
The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
Published 2012-06-20 · Modified
4.9EPSS 0.004
CVE-2006-0666
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
Published 2006-02-15 · Modified
4.9EPSS 0.004
CVE-2012-0723
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
Published 2012-07-30 · Modified
4.9EPSS 0.004
CVE-2024-49338
IBM App Connect Enterprise information disclosure
Published 2025-01-18 · Analyzed
4.9EPSS 0.004
CVE-2008-0589
The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.
Published 2008-02-05 · Modified
4.9EPSS 0.004
CVE-2008-1594
The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.
Published 2008-03-31 · Modified
4.9EPSS 0.004
CVE-2011-1375
IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
Published 2011-11-11 · Modified
4.9EPSS 0.004
CVE-2008-1597
The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."
Published 2008-03-31 · Modified
4.9EPSS 0.004
CVE-2011-0637
The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.
Published 2011-01-25 · Modified
4.9EPSS 0.004
CVE-2008-1595
The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.
Published 2008-03-31 · Modified
4.9EPSS 0.003
CVE-2007-4799
The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.
Published 2007-09-10 · Modified
4.9EPSS 0.003
CVE-2026-16866
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.8EPSS 0.003
CVE-2024-45073
IBM WebSphere Application Server cross-site scripting
Published 2024-09-30 · Analyzed
4.8EPSS 0.002
CVE-2026-2485
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
4.8EPSS 0.002
CVE-2014-0930
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
Published 2014-05-08 · Modified
4.7EPSS 0.005
CVE-2007-4228
rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.
Published 2007-08-08 · Modified
4.7EPSS 0.003
CVE-2008-1598
The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.
Published 2008-03-31 · Modified
4.7EPSS 0.003
← Prev22 / 25Next →