Ibm Vios vulnerabilities
239 known vulnerabilities affecting ibm/vios.
Total CVEs
239
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH114MEDIUM65LOW10
Vulnerabilities
Page 2 of 12
CVE-2026-17136P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17136 [CRITICAL] CWE-134 CVE-2026-17136: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
nvd
CVE-2026-17122P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17122 [CRITICAL] CWE-787 CVE-2026-17122: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2025-36251P3CRITICALCVSS 9.8v3.1.0v4.1.02025-11-13
CVE-2025-36251 [CRITICAL] CVE-2025-36251: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a r
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
nvd
CVE-2026-17145P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17145 [CRITICAL] CWE-269 CVE-2026-17145: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
nvd
CVE-2026-17138P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17138 [CRITICAL] CWE-121 CVE-2026-17138: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-16872P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16872 [CRITICAL] CWE-121 CVE-2026-16872: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2024-56347P3CRITICALCVSS 9.6v3.1v4.12025-03-18
CVE-2024-56347 [CRITICAL] CWE-114 CVE-2024-56347: IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to exe
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
nvd
CVE-2026-16894P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16894 [CRITICAL] CWE-787 CVE-2026-16894: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16913P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16913 [CRITICAL] CWE-787 CVE-2026-16913: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16885P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16885 [CRITICAL] CWE-121 CVE-2026-16885: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-17157P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17157 [CRITICAL] CWE-787 CVE-2026-17157: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-17024P2CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17024 [CRITICAL] CWE-295 CVE-2026-17024: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.
nvd
CVE-2013-4011P3HIGHCVSS 7.2PoCv2.2.2.22013-07-18
CVE-2013-4011 [HIGH] CVE-2013-4011: Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
nvd
CVE-2026-16862P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16862 [CRITICAL] CWE-787 CVE-2026-16862: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16864P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16864 [CRITICAL] CWE-787 CVE-2026-16864: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-18832P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-18832 [CRITICAL] CWE-787 CVE-2026-18832: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-17436P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17436 [CRITICAL] CWE-787 CVE-2026-17436: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-17160P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17160 [CRITICAL] CWE-190 CVE-2026-17160: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
nvd
CVE-2014-8904P3HIGHCVSS 7.2PoCv2.2.0.10v2.2.0.11+22 more2015-01-15
CVE-2014-8904 [HIGH] CWE-264 CVE-2014-8904: lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
nvd
CVE-2026-17003P3CRITICALCVSS 9.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17003 [CRITICAL] CWE-787 CVE-2026-17003: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.
nvd