Ibm

Vios

233 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 20.11.2020 04:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:15

IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.

  • EPSS 1.38%
  • Veröffentlicht 15.02.2017 19:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

  • EPSS 2.49%
  • Veröffentlicht 15.02.2017 19:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.

  • EPSS 8.42%
  • Veröffentlicht 08.08.2016 01:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.

  • EPSS 1.44%
  • Veröffentlicht 08.08.2016 01:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

  • EPSS 0.96%
  • Veröffentlicht 15.01.2015 22:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

  • EPSS 100%
  • Veröffentlicht 15.10.2014 00:55:02
  • Zuletzt bearbeitet 28.05.2026 18:16:23

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

  • EPSS 0.58%
  • Veröffentlicht 02.07.2014 10:35:25
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a se...

  • EPSS 0.87%
  • Veröffentlicht 08.06.2014 23:55:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 08.05.2014 10:55:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.