Ibm Vios vulnerabilities
239 known vulnerabilities affecting ibm/vios.
Total CVEs
239
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH114MEDIUM65LOW10
Vulnerabilities
Page 4 of 12
CVE-2026-16857P3HIGHCVSS 8.2≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16857 [HIGH] CWE-287 CVE-2026-16857: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network tr
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.
nvd
CVE-2026-16926P3CRITICALCVSS 9.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16926 [CRITICAL] CWE-73 CVE-2026-16926: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
nvd
CVE-2026-16909P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16909 [HIGH] CWE-128 CVE-2026-16909: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.
nvd
CVE-2026-16932P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16932 [HIGH] CWE-78 CVE-2026-16932: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable.
nvd
CVE-2026-15078P3HIGHCVSS 8.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-15078 [HIGH] CWE-295 CVE-2026-15078: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.
nvd
CVE-2026-16903P3CRITICALCVSS 9.6≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16903 [CRITICAL] CWE-787 CVE-2026-16903: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.
nvd
CVE-2026-16841P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16841 [HIGH] CWE-787 CVE-2026-16841: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
nvd
CVE-2026-16934P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16934 [HIGH] CWE-787 CVE-2026-16934: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow.
nvd
CVE-2026-16839P3CRITICALCVSS 9.4≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16839 [CRITICAL] CWE-125 CVE-2026-16839: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.
nvd
CVE-2026-16996P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16996 [HIGH] CWE-787 CVE-2026-16996: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow.
nvd
CVE-2026-19446P3HIGHCVSS 7.5≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-19446 [HIGH] CWE-400 CVE-2026-19446: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
nvd
CVE-2014-3977P4MEDIUMCVSS 6.9PoCv2.2.0.10v2.2.0.11+14 more2014-06-08
CVE-2014-3977 [MEDIUM] CVE-2014-3977: libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
nvd
CVE-2026-16847P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16847 [HIGH] CWE-787 CVE-2026-16847: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-16834P3CRITICALCVSS 9.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16834 [CRITICAL] CWE-190 CVE-2026-16834: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
nvd
CVE-2026-16814P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16814 [HIGH] CWE-787 CVE-2026-16814: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
nvd
CVE-2026-16875P3HIGHCVSS 7.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16875 [HIGH] CWE-78 CVE-2026-16875: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.
nvd
CVE-2026-19449P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-19449 [HIGH] CWE-269 CVE-2026-19449: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
nvd
CVE-2026-15061P3HIGHCVSS 8.2≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-15061 [HIGH] CWE-22 CVE-2026-15061: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
nvd
CVE-2026-18670P3CRITICALCVSS 9.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-18670 [CRITICAL] CWE-190 CVE-2026-18670: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
nvd
CVE-2026-19442P3HIGHCVSS 8.8≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-19442 [HIGH] CWE-822 CVE-2026-19442: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
nvd