CVE-2025-36244
- EPSS 0.02%
- Published 16.09.2025 14:38:08
- Last modified 17.09.2025 14:18:55
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
CVE-2025-33112
- EPSS 0.03%
- Published 10.06.2025 16:28:44
- Last modified 25.07.2025 19:09:10
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
CVE-2024-56347
- EPSS 0.07%
- Published 18.03.2025 16:16:09
- Last modified 25.07.2025 18:45:01
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
- EPSS 0.1%
- Published 18.03.2025 16:15:23
- Last modified 25.07.2025 18:44:46
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
CVE-2024-52906
- EPSS 0.02%
- Published 25.12.2024 15:15:07
- Last modified 25.07.2025 21:13:32
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
CVE-2024-47102
- EPSS 0.02%
- Published 25.12.2024 15:15:06
- Last modified 29.09.2025 16:15:35
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
CVE-2024-47115
- EPSS 0.07%
- Published 07.12.2024 13:19:14
- Last modified 21.01.2025 16:15:46
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
CVE-2024-27260
- EPSS 0.07%
- Published 16.05.2024 17:16:01
- Last modified 29.07.2025 17:21:29
IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
CVE-2024-27273
- EPSS 0.02%
- Published 07.05.2024 21:15:09
- Last modified 18.08.2025 15:19:57
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 2849...
CVE-2024-25021
- EPSS 0.11%
- Published 22.02.2024 12:15:46
- Last modified 06.05.2025 16:47:26
IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.