Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Vios
Total 237 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18824 1 Ibm 2 Aix, Vios 2026-09-04 N/A 8.4 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-16821 1 Ibm 2 Aix, Vios 2026-09-02 N/A 7.0 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
CVE-2026-0992 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 2.9 LOW
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
CVE-2026-0989 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 3.7 LOW
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.
CVE-2026-0990 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-09-01 N/A 5.9 MEDIUM
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.
CVE-2026-6732 3 Ibm, Redhat, Xmlsoft 7 Aix, Vios, Enterprise Linux and 4 more 2026-08-31 N/A 6.5 MEDIUM
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
CVE-2026-19437 1 Ibm 2 Aix, Vios 2026-08-27 N/A 8.1 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CVE-2026-17145 1 Ibm 2 Aix, Vios 2026-08-27 N/A 9.8 CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
CVE-2026-17124 1 Ibm 2 Aix, Vios 2026-08-27 N/A 7.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.
CVE-2026-17006 1 Ibm 2 Aix, Vios 2026-08-27 N/A 8.3 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CVE-2026-16991 1 Ibm 2 Aix, Vios 2026-08-27 N/A 7.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
CVE-2026-16919 1 Ibm 2 Aix, Vios 2026-08-27 N/A 9.8 CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
CVE-2026-19783 1 Ibm 2 Aix, Vios 2026-08-26 N/A 6.7 MEDIUM
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.
CVE-2026-16945 1 Ibm 2 Aix, Vios 2026-08-26 N/A 7.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
CVE-2026-16935 1 Ibm 2 Aix, Vios 2026-08-26 N/A 7.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2026-16838 1 Ibm 2 Aix, Vios 2026-08-26 N/A 7.0 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2026-19449 1 Ibm 2 Aix, Vios 2026-08-25 N/A 8.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
CVE-2026-19446 1 Ibm 2 Aix, Vios 2026-08-25 N/A 7.5 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
CVE-2026-19448 1 Ibm 2 Aix, Vios 2026-08-25 N/A 6.5 MEDIUM
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.
CVE-2026-17171 1 Ibm 2 Aix, Vios 2026-08-25 N/A 7.8 HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.