cbcvebase.

Ibm Vios vulnerabilities

94 known vulnerabilities affecting ibm/vios.

Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH37MEDIUM43LOW7

Vulnerabilities

Page 2 of 5
CVE-2026-6732P3HIGHCVSS 7.5≥ 4.1.0, < 4.1.1.30v4.1.2.02026-04-23
CVE-2026-6732 [HIGH] CWE-843 CVE-2026-6732: A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafte A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial
nvd
CVE-2025-33112P3HIGHCVSS 8.4v4.1.12025-06-10
CVE-2025-33112 [HIGH] CWE-23 CVE-2025-33112: IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploi IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
nvd
CVE-2025-62230P3HIGHCVSS 7.3≥ 4.1.0, < 4.1.1.30v4.1.2.02025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvd
CVE-2013-3005P3HIGHCVSS 8.5v2.2.2.22013-07-06
CVE-2013-3005 [HIGH] CWE-264 CVE-2013-3005: The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows r The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
nvd
CVE-2022-41290P3HIGHCVSS 8.4v3.12022-12-23
CVE-2022-41290 [HIGH] CWE-250 CVE-2022-41290: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690.
nvd
CVE-2023-26286P3HIGHCVSS 7.8v3.12023-04-26
CVE-2023-26286 [HIGH] CVE-2023-26286: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.
nvd
CVE-2024-47115P3HIGHCVSS 7.8v3.1v4.12024-12-07
CVE-2024-47115 [HIGH] CWE-78 CVE-2024-47115: IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
nvd
CVE-2020-4829P3HIGHCVSS 7.8v3.12020-12-10
CVE-2020-4829 [HIGH] CVE-2020-4829: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user c IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.
nvd
CVE-2021-29801P3HIGHCVSS 7.8v3.12021-08-26
CVE-2021-29801 [HIGH] CVE-2021-29801: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.
nvd
CVE-2021-29741P3HIGHCVSS 7.8v3.12021-08-02
CVE-2021-29741 [HIGH] CVE-2021-29741: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ks IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.
nvd
CVE-2023-45166P3HIGHCVSS 7.8v3.12023-12-13
CVE-2023-45166 [HIGH] CVE-2023-45166: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges. IBM X-Force ID: 267964.
nvd
CVE-2022-36768P3HIGHCVSS 7.8v3.12022-09-13
CVE-2022-36768 [HIGH] CVE-2022-36768: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.
nvd
CVE-2022-34356P3HIGHCVSS 7.8v3.12022-09-13
CVE-2022-34356 [HIGH] CVE-2022-34356: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.
nvd
CVE-2022-22351P3HIGHCVSS 8.6≥ 3.1.1, < 3.1.1.60≥ 3.1.2, < 3.1.2.40+2 more2022-03-07
CVE-2022-22351 [HIGH] CVE-2022-22351: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vuln IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396
nvd
CVE-2021-38990P3HIGHCVSS 7.8v3.12022-01-10
CVE-2021-38990 [HIGH] CVE-2021-38990: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.
nvd
CVE-2021-38991P3HIGHCVSS 7.8v3.12022-01-11
CVE-2021-38991 [HIGH] CVE-2021-38991: IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.
nvd
CVE-2024-27273P3HIGHCVSS 7.8v3.1v4.12024-05-07
CVE-2024-27273 [HIGH] CWE-266 CVE-2024-27273: IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could po IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.
nvd
CVE-2023-45170P3HIGHCVSS 7.8v3.12023-12-13
CVE-2023-45170 [HIGH] CVE-2023-45170: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service. IBM X-Force ID: 267968.
nvd
CVE-2023-45174P3HIGHCVSS 7.8v3.12023-12-13
CVE-2023-45174 [HIGH] CVE-2023-45174: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Force ID: 267972.
nvd
CVE-2026-0990P3MEDIUMCVSS 5.9≥ 4.1.0, < 4.1.1.30v4.1.2.02026-01-15
CVE-2026-0990 [MEDIUM] CWE-674 CVE-2026-0990: A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occur A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recu
nvd
Ibm Vios vulnerabilities | cvebase