cbcvebase.

Ibm Vios vulnerabilities

239 known vulnerabilities affecting ibm/vios.

Total CVEs
239
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL50HIGH114MEDIUM65LOW10

Vulnerabilities

Page 9 of 12
CVE-2026-16914P3MEDIUMCVSS 6.7≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16914 [MEDIUM] CWE-787 CVE-2026-16914: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
nvd
CVE-2026-16951P3MEDIUMCVSS 6.7≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16951 [MEDIUM] CWE-787 CVE-2026-16951: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
nvd
CVE-2026-16964P3MEDIUMCVSS 6.5≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16964 [MEDIUM] CWE-200 CVE-2026-16964: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.
nvd
CVE-2026-16935P3HIGHCVSS 7.0≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16935 [HIGH] CWE-367 CVE-2026-16935: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2026-16833P4MEDIUMCVSS 5.3≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16833 [MEDIUM] CWE-125 CVE-2026-16833: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.
nvd
CVE-2026-16838P4HIGHCVSS 7.0≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16838 [HIGH] CWE-367 CVE-2026-16838: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
nvd
CVE-2013-3035P4HIGHCVSS 7.1v2.2.1.42013-06-21
CVE-2013-3035 [HIGH] CWE-20 CVE-2013-3035: The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
nvd
CVE-2026-16827P4MEDIUMCVSS 5.9≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16827 [MEDIUM] CWE-908 CVE-2026-16827: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
nvd
CVE-2012-4845P4MEDIUMCVSS 6.8v2.2.1.42012-10-20
CVE-2012-4845 [MEDIUM] CWE-264 CVE-2012-4845: The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privil The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
nvd
CVE-2025-36244P4MEDIUMCVSS 5.5v3.1v4.12025-09-16
CVE-2025-36244 [MEDIUM] CWE-454 CVE-2025-36244: IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, cou IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
nvd
CVE-2010-0960P4HIGHCVSS 7.2v2.12010-03-10
CVE-2010-0960 [HIGH] CWE-119 CVE-2010-0960: Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to ga Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2010-0961P4HIGHCVSS 7.2v2.12010-03-10
CVE-2010-0961 [HIGH] CWE-119 CVE-2010-0961: Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to g Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2012-2200P4HIGHCVSS 7.2v2.2.1.42012-06-27
CVE-2012-2200 [HIGH] CWE-264 CVE-2012-2200: The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows l The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.
nvd
CVE-2026-17007P4HIGHCVSS 7.1≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-17007 [HIGH] CWE-125 CVE-2026-17007: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
nvd
CVE-2012-4817P4MEDIUMCVSS 5.0v1.4.1.2v1.5.1.1+15 more2012-09-14
CVE-2012-4817 [MEDIUM] CVE-2012-4817: The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, d The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2012-0745P4HIGHCVSS 7.2v2.1.0.10v2.1.2.12+9 more2012-05-04
CVE-2012-0745 [HIGH] CWE-264 CVE-2012-0745: The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not proper The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2020-4887P4MEDIUMCVSS 5.5v3.12021-01-20
CVE-2020-4887 [MEDIUM] CVE-2020-4887: IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any directory. IBM X-Force ID: 190911.
nvd
CVE-2026-16973P4MEDIUMCVSS 5.5≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-20
CVE-2026-16973 [MEDIUM] CWE-200 CVE-2026-16973: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.
nvd
CVE-2026-16846P4MEDIUMCVSS 6.5≥ 4.1.0, < 4.1.0.50≥ 4.1.1.0, < 4.1.1.30+1 more2026-08-19
CVE-2026-16846 [MEDIUM] CWE-476 CVE-2026-16846: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null pointer dereference.
nvd
CVE-2021-29860P4MEDIUMCVSS 6.2v3.1.0v3.12021-11-17
CVE-2021-29860 [MEDIUM] CVE-2021-29860: IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive information. IBM X-Force ID: 206084.
nvd
Ibm Vios vulnerabilities | cvebase