Aix

Vendor:

First CVE: Mar 1, 1992 · Active for 34 years

836
Total CVEs
More Total CVEs than 100% of tracked products
24.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Aix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1992
34 years ago
Most Recent CVE
Jun 22, 2026
35 days ago

CVE Severity & Scoring

Aix836 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local118 (14.1%)
Network350 (41.9%)
Unknown360 (43.1%)
Physical0 (0.0%)
Adjacent Network8 (1.0%)
Attack Complexity
Low449 (53.7%)
High27 (3.2%)
Unknown360 (43.1%)
User Interaction
None390 (46.7%)
Unknown360 (43.1%)
Required86 (10.3%)
Privileges Required
Low257 (30.7%)
High22 (2.6%)
None197 (23.6%)
Unknown360 (43.1%)

Top CVEs

Signals from CVEs in this product scope (836 CVEs).

836 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.090NOYES
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to
Oct 15, 200910.079NOYES
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
Buffer overflow of rlogin program using TERM environmental variable.
Feb 6, 199710.067NOYES
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Dec 18, 19965.063NOYES
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th
Aug 14, 200110.060NOYES
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Jan 5, 19985.060NOYES
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the
Aug 10, 20099.359NOYES
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Apr 8, 199810.054NOYES

Exploit Exposure

Signals from CVEs in this product scope (836 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
0.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
77 CVEs
9.2% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (836 CVEs).

Media Mentions

Signals from CVEs in this product scope (836 CVEs).

Top CNAs Publishing CVEs For Aix

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.3.475.40.4%00
7.3.318.40.2%00
7.3.0.036.50.5%00
7.3.018.61.2%00
7.3466.80.3%01
7.2.5.10027.00.7%00
7.2.5.127.00.7%00
7.2.5.036.50.5%00
7.2.514.70.4%00
7.2.4.015.50.2%00
7.2.414.70.4%00
7.2.314.70.4%00
7.2.219.12.7%00
7.2.119.12.7%00
7.2.035.70.3%00
7.2636.80.5%03
7.1.526.91.5%00
7.1.419.12.7%00
7.1.319.12.7%00
7.1.227.82.3%00