← Back

Vios

vios

Vendor: Ibm • 92 CVEs

CVEs (92)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Aix
Vios
Jun 17, 2026
Aug 26, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.
1Ibm
2Aix
Vios
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.
1Ibm
2Aix
Vios
Jun 17, 2026
Jun 28, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
1Ibm
2Aix
Vios
Jun 17, 2026
Jan 20, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any directory. IBM X-Force ID: 190911.
1Ibm
2Aix
Vios
Jun 17, 2026
Dec 10, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.
3Fedoraproject
IbmOracle
6Aix
Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+3 more
Jun 17, 2026
Nov 20, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
1Ibm
2Aix
Vios
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
1Ibm
2Aix
Vios
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
1Ibm
2Aix
Vios
May 6, 2026
Aug 8, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packet...Show more
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.Show less
1Ibm
2Aix
Vios
May 6, 2026
Aug 8, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
1Ibm
2Aix
Vios
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.
1Ibm
2Aix
Vios
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
11Apple
DebianFedoraproject+8 more
20Aix
DatabaseDebian Linux+17 more
May 28, 2026
Oct 15, 2014
N/A· v4
3.4 LOW· v3
4.3 MEDIUM· v2
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.Show less
1Ibm
2Aix
Vios
May 6, 2026
Jul 2, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable...Show more
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.Show less
1Ibm
2Aix
Vios
May 6, 2026
Jun 8, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
1Ibm
2Aix
Vios
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
1Ibm
2Aix
Vios
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
1Ibm
2Aix
Vios
Apr 29, 2026
Jul 6, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via uns...Show more
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.Show less
1Ibm
2Aix
Vios
Apr 29, 2026
Jun 21, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
1Ibm
2Aix
Vios
Apr 29, 2026
Oct 20, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid i...Show more
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.Show less