cbcvebase.

Ibm Vios vulnerabilities

239 known vulnerabilities affecting ibm/vios.

Total CVEs
239
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH114MEDIUM65LOW10

Vulnerabilities

Page 1 of 12
CVE-2009-3699P2CRITICALCVSS 10.0PoC≤ 2.1.0v1.4+3 more2009-10-15
CVE-2009-3699 [CRITICAL] CWE-119 CVE-2009-3699: Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3 Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
nvd
CVE-2010-1039P2CRITICALCVSS 10.0PoC≤ 1.5v1.4+1 more2010-05-20
CVE-2010-1039 [CRITICAL] CWE-134 CVE-2010-1039: Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid direct
nvd
CVE-2014-3566P3LOWCVSS 3.4PoCv2.2.0.10v2.2.0.11+22 more2014-10-15
CVE-2014-3566 [LOW] CWE-310 CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
nvd
CVE-2023-28528P3HIGHCVSS 7.8PoCv3.12023-04-28
CVE-2023-28528 [HIGH] CWE-78 CVE-2023-28528: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.
nvd
CVE-2026-15068P2CRITICALCVSS 9.9≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-15068 [CRITICAL] CWE-78 CVE-2026-15068: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to exe IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-18835P2CRITICALCVSS 9.9≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-18835 [CRITICAL] CWE-78 CVE-2026-18835: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-16816P2CRITICALCVSS 9.9≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16816 [CRITICAL] CWE-78 CVE-2026-16816: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17142P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17142 [CRITICAL] CWE-287 CVE-2026-17142: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.
nvd
CVE-2024-56346P2CRITICALCVSS 10.0v3.1v4.12025-03-18
CVE-2024-56346 [CRITICAL] CWE-114 CVE-2024-56346: IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary co IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
nvd
CVE-2016-8972P3HIGHCVSS 7.8PoCv2.2.0.0v2.2.0.10+37 more2017-02-15
CVE-2016-8972 [HIGH] CWE-264 CVE-2016-8972: IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
nvd
CVE-2026-16882P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16882 [CRITICAL] CWE-78 CVE-2026-16882: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2016-6079P3HIGHCVSS 7.8PoCv2.2.0.0v2.2.0.10+37 more2017-02-15
CVE-2016-6079 [HIGH] CWE-264 CVE-2016-6079: IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally auth IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
nvd
CVE-2026-16919P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16919 [CRITICAL] CWE-843 CVE-2026-16919: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
nvd
CVE-2026-16656P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16656 [CRITICAL] CWE-287 CVE-2026-16656: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
nvd
CVE-2026-17000P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17000 [CRITICAL] CWE-287 CVE-2026-17000: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.
nvd
CVE-2026-18824P2HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-18824 [HIGH] CWE-78 CVE-2026-18824: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-16840P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16840 [CRITICAL] CWE-787 CVE-2026-16840: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2025-36236P2CRITICALCVSS 9.1v3.1.0v4.1.0+2 more2025-11-13
CVE-2025-36236 [CRITICAL] CWE-22 CVE-2025-36236: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
nvd
CVE-2025-36250P2CRITICALCVSS 9.8v3.1.0v4.1.02025-11-13
CVE-2025-36250 [CRITICAL] CVE-2025-36250: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
nvd
CVE-2026-17118P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17118 [CRITICAL] CWE-416 CVE-2026-17118: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
nvd
1 / 12Next →
Ibm Vios vulnerabilities | cvebase