CVE-2025-36096
- EPSS 0.3%
- Veröffentlicht 13.11.2025 22:15:50
- Zuletzt bearbeitet 19.11.2025 22:11:50
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
CVE-2025-36236
- EPSS 0.49%
- Veröffentlicht 13.11.2025 22:15:50
- Zuletzt bearbeitet 19.11.2025 22:11:10
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary ...
CVE-2025-36250
- EPSS 0.67%
- Veröffentlicht 13.11.2025 22:15:50
- Zuletzt bearbeitet 19.11.2025 22:08:58
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a v...
CVE-2025-62230
- EPSS 0.26%
- Veröffentlicht 30.10.2025 05:19:40
- Zuletzt bearbeitet 01.07.2026 15:13:56
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can c...
CVE-2025-62231
- EPSS 0.28%
- Veröffentlicht 30.10.2025 05:15:39
- Zuletzt bearbeitet 01.07.2026 15:17:04
A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation m...
CVE-2025-36244
- EPSS 0.12%
- Veröffentlicht 16.09.2025 14:38:08
- Zuletzt bearbeitet 17.10.2025 14:34:38
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
CVE-2025-8732
- EPSS 0.2%
- Veröffentlicht 08.08.2025 16:32:06
- Zuletzt bearbeitet 01.07.2026 15:25:19
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a ...
CVE-2025-33112
- EPSS 0.19%
- Veröffentlicht 10.06.2025 16:28:44
- Zuletzt bearbeitet 25.07.2025 19:09:10
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
CVE-2024-52906
- EPSS 0.13%
- Veröffentlicht 25.12.2024 15:15:07
- Zuletzt bearbeitet 25.07.2025 21:13:32
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
CVE-2024-47102
- EPSS 0.15%
- Veröffentlicht 25.12.2024 15:15:06
- Zuletzt bearbeitet 29.09.2025 16:15:35
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.