Skip to main content

Vendor/product archive

ibm / vios CVEs

Beta · best-effort

92 CVEs tagged to ibm / vios5 Critical, 36 High, 44 Medium, 7 Low, 0 Unrated.

CVE-2025-36251

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls.…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36250

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to impro…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36236

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36096

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-62230

Published Oct 30, 2025

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detachi…

CVSS 7.3 · High

CVE-2025-62231

Published Oct 30, 2025

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If…

CVSS 7.3 · High

CVE-2025-36244

Published Sep 16, 2025

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-33112

Published Jun 10, 2025

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of p…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52906

Published Dec 25, 2024

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47102

Published Dec 25, 2024

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47115

Published Dec 7, 2024

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27260

Published May 16, 2024

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID:…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27273

Published May 7, 2024

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25021

Published Feb 22, 2024

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45171

Published Jan 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45169

Published Jan 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 26…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45175

Published Jan 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 26…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45173

Published Jan 11, 2024

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 26797…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45172

Published Dec 19, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45174

Published Dec 13, 2023

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service. IBM X-Fo…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 92 CVEsPage 1 of 4