cbcvebase.

Ibm Vios vulnerabilities

94 known vulnerabilities affecting ibm/vios.

Total CVEs
94
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH37MEDIUM43LOW7

Vulnerabilities

Page 5 of 5
CVE-2024-47102P4MEDIUMCVSS 5.5v3.1v4.12024-12-25
CVE-2024-47102 [MEDIUM] CWE-863 CVE-2024-47102: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerabil IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
nvd
CVE-2024-52906P4MEDIUMCVSS 5.5v3.1v4.12024-12-25
CVE-2024-52906 [MEDIUM] CWE-362 CVE-2024-52906: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerab IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
nvd
CVE-2022-22350P4MEDIUMCVSS 5.5v3.12022-03-02
CVE-2022-22350 [MEDIUM] CVE-2022-22350: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerabili IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
nvd
CVE-2026-0989P4LOWCVSS 3.7≥ 4.1.0, < 4.1.1.30v4.1.2.02026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2014-0930P4MEDIUMCVSS 4.7v2.2.0.10v2.2.0.11+8 more2014-05-08
CVE-2014-0930 [MEDIUM] CVE-2014-0930: The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a d The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
nvd
CVE-2012-0723P4MEDIUMCVSS 4.9v2.2.1.42012-07-30
CVE-2012-0723 [MEDIUM] CWE-20 CVE-2012-0723: The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement t The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
nvd
CVE-2021-29693P4MEDIUMCVSS 4.4v3.12021-06-28
CVE-2021-29693 [MEDIUM] CVE-2021-29693: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privilege IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
nvd
CVE-2021-38955P4MEDIUMCVSS 4.4v3.12022-03-01
CVE-2021-38955 [MEDIUM] CVE-2021-38955: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a den IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.
nvd
CVE-2016-0266P4LOWCVSS 3.7v2.2.0.10v2.2.0.11+31 more2016-08-08
CVE-2016-0266 [LOW] CWE-254 CVE-2016-0266: IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2025-8732P4LOWCVSS 3.3≥ 4.1.0, < 4.1.1.30v4.1.2.02025-08-08
CVE-2025-8732 [LOW] CWE-404 CVE-2025-8732: A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnera A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vuln
nvd
CVE-2026-0992P4LOWCVSS 2.9≥ 4.1.0, < 4.1.1.30v4.1.2.02026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvd
CVE-2012-2192P4MEDIUMCVSS 4.9v2.2.1.42012-06-20
CVE-2012-2192 [MEDIUM] CWE-399 CVE-2012-2192: The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
nvd
CVE-2022-43382P4MEDIUMCVSS 4.4v3.12022-12-20
CVE-2022-43382 [MEDIUM] CWE-399 CVE-2022-43382: IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vu IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.
nvd
CVE-2012-4833P4LOWCVSS 2.1v2.2.1.42012-10-01
CVE-2012-4833 [LOW] CWE-264 CVE-2012-4833: fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
nvd
Ibm Vios vulnerabilities | cvebase