cbcvebase.

Ibm Vios vulnerabilities

239 known vulnerabilities affecting ibm/vios.

Total CVEs
239
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH114MEDIUM65LOW10

Vulnerabilities

Page 3 of 12
CVE-2026-16865P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16865 [HIGH] CWE-78 CVE-2026-16865: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.
nvd
CVE-2026-16917P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16917 [CRITICAL] CWE-190 CVE-2026-16917: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
nvd
CVE-2014-3074P3HIGHCVSS 7.2PoCv2.2.0.10v2.2.0.11+14 more2014-07-02
CVE-2014-3074 [HIGH] CWE-264 CVE-2014-3074: The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 roo The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
nvd
CVE-2026-16850P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16850 [HIGH] CWE-269 CVE-2026-16850: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.
nvd
CVE-2026-16877P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16877 [HIGH] CWE-121 CVE-2026-16877: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-17168P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17168 [HIGH] CWE-787 CVE-2026-17168: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
nvd
CVE-2026-16842P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16842 [HIGH] CWE-78 CVE-2026-16842: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-16844P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16844 [HIGH] CWE-78 CVE-2026-16844: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17141P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17141 [CRITICAL] CWE-787 CVE-2026-17141: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-17152P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17152 [CRITICAL] CWE-787 CVE-2026-17152: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-16845P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16845 [CRITICAL] CWE-787 CVE-2026-16845: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-16822P3CRITICALCVSS 9.3≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16822 [CRITICAL] CWE-295 CVE-2026-16822: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
nvd
CVE-2026-16911P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16911 [HIGH] CWE-121 CVE-2026-16911: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16848P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16848 [HIGH] CWE-78 CVE-2026-16848: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.
nvd
CVE-2026-16686P3HIGHCVSS 8.2≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16686 [HIGH] CWE-287 CVE-2026-16686: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported f IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication.
nvd
CVE-2026-19437P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-19437 [CRITICAL] CWE-787 CVE-2026-19437: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-17040P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17040 [CRITICAL] CWE-120 CVE-2026-17040: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
nvd
CVE-2026-17006P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17006 [CRITICAL] CWE-787 CVE-2026-17006: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-15065P3CRITICALCVSS 9.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-15065 [CRITICAL] CWE-312 CVE-2026-15065: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.
nvd
CVE-2026-16901P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16901 [HIGH] CWE-787 CVE-2026-16901: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
nvd
Ibm Vios vulnerabilities | cvebase