VendorsIBMaixall versions
Vulnerabilities

IBM AIX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

992CVEs
CVE-2026-17124
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-16874
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2026-16869
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2026-16945
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-16873
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.002
CVE-2026-16946
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.002
CVE-2026-16703
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.8EPSS 0.001
CVE-2026-16991
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16937
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-13367
IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
Published 2026-08-12 · Analyzed
7.8EPSS 0.001
CVE-2026-16989
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16944
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-19783
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16821
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-28 · Analyzed
7.8EPSS 0.001
CVE-2026-16925
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16923
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16935
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
7.8EPSS 0.001
CVE-2026-16819
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
7.7EPSS 0.001
CVE-2007-4938
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
Published 2007-09-18 · Modified
7.61 PoCEPSS 0.160
CVE-2025-0966
IBM InfoSphere Information Server SQL injection
Published 2025-06-25 · Analyzed
7.6EPSS 0.003
CVE-2025-33104
IBM WebSphere Application Server cross
Published 2025-05-14 · Analyzed
7.6EPSS 0.002
CVE-2003-0681
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Published 2003-09-18 · Modified
7.51 PoCEPSS 0.224
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0041
Buffer overflow in NLS (Natural Language Service).
Published 1999-09-29 · Modified
7.52 PoCEPSS 0.091
CVE-2007-1043
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
Published 2007-02-21 · Modified
7.51 PoCEPSS 0.083
CVE-1999-0057
Vacation program allows command execution by remote users through a sendmail command.
Published 1999-09-29 · Modified
7.5EPSS 0.082
CVE-2006-4254
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.
Published 2006-08-21 · Modified
7.51 PoCEPSS 0.079
CVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Published 2002-07-12 · Modified
7.5EPSS 0.066
CVE-2012-0711
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
Published 2012-03-20 · Modified
7.5EPSS 0.046
CVE-2007-1915
Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
7.5EPSS 0.044
CVE-1999-0085
Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
Published 1999-09-29 · Modified
7.5EPSS 0.039
CVE-2005-3396
Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
Published 2005-11-01 · Modified
7.5EPSS 0.034
CVE-2005-3504
Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.
Published 2005-11-05 · Modified
7.5EPSS 0.032
CVE-1999-1574
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
Published 2005-04-21 · Modified
7.5EPSS 0.030
CVE-2002-1622
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
Published 2005-03-26 · Modified
7.5EPSS 0.030
CVE-2021-29725
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
Published 2021-07-15 · Modified
7.5EPSS 0.029
CVE-2020-4135
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.
Published 2020-02-19 · Modified
7.5EPSS 0.029
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-2020-4494
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation which can result in access to unauthorized resources. IBM X-Force ID: 182019.
Published 2020-06-15 · Modified
7.5EPSS 0.022
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
← Prev7 / 25Next →