VendorsIBMviosall versions
Vulnerabilities

IBM Virtual I/O Server (VIOS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

237CVEs
CVE-2023-45173
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2023-45175
IBM AIX denial of service
Published 2024-01-11 · Modified
6.2EPSS 0.002
CVE-2023-40371
IBM AIX information disclosure
Published 2023-08-24 · Modified
6.2EPSS 0.001
CVE-2026-0990
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
Published 2026-01-15 · Analyzed
5.9EPSS 0.010
CVE-2026-16827
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.9EPSS 0.004
CVE-2026-16883
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.5EPSS 0.001
CVE-2024-47102
IBM AIX denial of service
Published 2024-12-25 · Modified
5.5EPSS 0.001
CVE-2026-16973
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-16952
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-16855
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.5EPSS 0.001
CVE-2024-52906
IBM AIX denial of service
Published 2024-12-25 · Analyzed
5.5EPSS 0.001
CVE-2026-18822
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-17009
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-20 · Analyzed
5.5EPSS 0.001
CVE-2026-16833
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.004
CVE-2026-16829
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
5.3EPSS 0.003
CVE-2020-4788
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
Published 2020-11-20 · Modified
5.1EPSS 0.004
CVE-2012-4817
The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.
Published 2012-09-14 · Modified
5.0EPSS 0.076
CVE-2021-29693
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.
Published 2021-06-28 · Modified
4.9EPSS 0.006
CVE-2012-2192
The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.
Published 2012-06-20 · Modified
4.9EPSS 0.004
CVE-2012-0723
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
Published 2012-07-30 · Modified
4.9EPSS 0.004
CVE-2026-16866
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.8EPSS 0.003
CVE-2014-0930
The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.
Published 2014-05-08 · Modified
4.7EPSS 0.005
CVE-2021-38955
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.
Published 2022-03-01 · Modified
4.4EPSS 0.002
CVE-2026-16897
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.4EPSS 0.001
CVE-2014-3566
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Published 2014-10-15 · Modified
4.3EPSS 1.000
CVE-2016-0281
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.
Published 2016-08-08 · Modified
4.3EPSS 0.084
CVE-2016-0266
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Published 2016-08-08 · Modified
4.3EPSS 0.014
CVE-2026-16886
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-16849
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-16825
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
4.2EPSS 0.003
CVE-2026-0989
Libxml2: unbounded relaxng include recursion leading to stack overflow
Published 2026-01-15 · Analyzed
3.7EPSS 0.005
CVE-2026-16888
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.7EPSS 0.005
CVE-2026-16890
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.6EPSS 0.001
CVE-2025-8732
libxml2 xmlcatalog xmlParseSGMLCatalog recursion
Published 2025-08-08 · Analyzed
3.3EPSS 0.002
CVE-2026-16891
Vulnerabilities in IBM AIX and PowerVM VIOS
Published 2026-08-19 · Analyzed
3.3EPSS 0.001
CVE-2026-0992
Libxml2: libxml2: denial of service via crafted xml catalogs
Published 2026-01-15 · Analyzed
2.9EPSS 0.005
CVE-2012-4833
fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.
Published 2012-10-01 · Modified
2.1EPSS 0.004
← Prev6 / 6