Vulnerabilities > IBM > Vios > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-26 CVE-2021-29801 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges.
local
low complexity
ibm
7.2
2021-08-02 CVE-2021-29741 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges.
local
low complexity
ibm
7.2
2020-12-10 CVE-2020-4829 Unspecified vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges.
local
low complexity
ibm
7.2
2017-02-15 CVE-2016-8972 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client.
local
low complexity
ibm CWE-264
7.2
2017-02-15 CVE-2016-6079 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
local
low complexity
ibm CWE-264
7.2
2015-01-15 CVE-2014-8904 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.
local
low complexity
ibm CWE-264
7.2
2014-07-02 CVE-2014-3074 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
local
low complexity
ibm CWE-264
7.2
2013-07-18 CVE-2013-4011 Local Privilege Escalation vulnerability in IBM AIX
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.
local
low complexity
ibm
7.2
2013-07-06 CVE-2013-3005 Permissions, Privileges, and Access Controls vulnerability in IBM AIX and Vios
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
network
ibm CWE-264
8.5
2013-06-21 CVE-2013-3035 Improper Input Validation vulnerability in IBM AIX and Vios
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
network
ibm CWE-20
7.1