VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2025-14808
IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information
Published 2026-03-25 · Analyzed
3.1EPSS 0.002
CVE-2026-0992
Libxml2: libxml2: denial of service via crafted xml catalogs
Published 2026-01-15 · Analyzed
2.9EPSS 0.005
CVE-2024-52905
IBM Sterling B2B Integrator information disclosure
Published 2025-03-10 · Analyzed
2.7EPSS 0.003
CVE-2005-0156
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
Published 2005-02-07 · Modified
2.11 PoCEPSS 0.013
CVE-1999-1408
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
Published 2001-09-12 · Modified
2.11 PoCEPSS 0.010
CVE-1999-1117
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.007
CVE-2000-0873
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
Published 2001-01-22 · Modified
2.11 PoCEPSS 0.006
CVE-2005-2238
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
Published 2005-07-12 · Modified
2.1EPSS 0.005
CVE-1999-0851
Denial of service in BIND named via naptr.
Published 2000-01-04 · Modified
2.1EPSS 0.004
CVE-2012-4833
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
Published 2012-10-01 · Modified
2.1EPSS 0.004
CVE-2014-4805
IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
Published 2014-09-04 · Modified
2.1EPSS 0.004
CVE-2005-4273
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
Published 2005-12-15 · Modified
2.1EPSS 0.004
CVE-2005-0991
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
Published 2005-04-06 · Modified
2.1EPSS 0.004
CVE-2007-6680
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.
Published 2008-01-10 · Modified
2.1EPSS 0.004
CVE-2009-1292
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
Published 2009-04-14 · Modified
2.1EPSS 0.004
CVE-2006-5004
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
Published 2006-09-27 · Modified
2.1EPSS 0.004
CVE-2002-0790
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
Published 2003-04-02 · Modified
2.1EPSS 0.004
CVE-2004-0828
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
Published 2004-09-28 · Modified
2.1EPSS 0.003
CVE-2005-0261
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
Published 2005-02-10 · Modified
2.1EPSS 0.003
CVE-2005-3289
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
Published 2005-10-23 · Modified
2.1EPSS 0.003
CVE-2011-3982
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.
Published 2011-10-05 · Modified
2.1EPSS 0.003
CVE-2000-0080
AIX techlibss allows local users to overwrite files via a symlink attack.
Published 2001-01-22 · Modified
2.1EPSS 0.003
CVE-1999-0694
Denial of service in AIX ptrace system call allows local users to crash the system.
Published 2000-01-18 · Modified
2.1EPSS 0.003
CVE-2002-1687
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
Published 2005-06-21 · Modified
2.1EPSS 0.003
CVE-2003-1437
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Published 2007-10-23 · Modified
2.1EPSS 0.002
CVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Published 2000-02-04 · Modified
1.9EPSS 0.009
CVE-2014-6195
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Windows, before 6.2.5.3 on AIX and Linux x86, and before 6.2.5.4 on Linux Z and Solaris; 6.3 before 6.3.2.1 on AIX, before 6.3.2.2 on Windows, and before 6.3.2.3 on Linux; 6.4 before 6.4.2.1; and 7.1 before 7.1.1 in IBM TSM for Mail, when the Data Protection for Lotus Domino component is used, allow local users to bypass authentication and restore a Domino database or transaction-log backup via unspecified vectors.
Published 2015-02-14 · Modified
1.9EPSS 0.004
CVE-2010-3406
Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.
Published 2010-09-16 · Modified
1.7EPSS 0.003
CVE-2005-1176
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
Published 2005-04-19 · Modified
1.2EPSS 0.003
CVE-1999-1486
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
Published 2004-09-01 · Modified
1.2EPSS 0.003
CVE-1999-1480
(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.
Published 2001-09-12 · Modified
1.2EPSS 0.002
CVE-1999-0627
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.
Published 1999-09-29 · Modified
n/aEPSS 0.068
← Prev25 / 25