<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM AIX</title>
  <link>https://cvedaily.com/pages/tags/ibm-aix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-aix.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM AIX</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-36251 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36251</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36251</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36250 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36250</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36250</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls.  This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36236 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36236</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36236</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-36096 – IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36096</guid>
    <pubDate>Thu, 13 Nov 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-36096</strong></p>
  <p>IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36244 – IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36244</guid>
    <pubDate>Tue, 16 Sep 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36244</strong></p>
  <p>IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-454</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33112 – IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33112</guid>
    <pubDate>Tue, 10 Jun 2025 17:23:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33112</strong></p>
  <p>IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56347 – IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56347</guid>
    <pubDate>Tue, 18 Mar 2025 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56347</strong></p>
  <p>IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56346 – IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56346</guid>
    <pubDate>Tue, 18 Mar 2025 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56346</strong></p>
  <p>IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52906 – IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1



could allow a non-privileged local user t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52906</guid>
    <pubDate>Wed, 25 Dec 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52906</strong></p>
  <p>IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1    could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47102 – IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1

could allow a non-privileged local user to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47102</guid>
    <pubDate>Wed, 25 Dec 2024 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47102</strong></p>
  <p>IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1  could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47115 – IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47115</guid>
    <pubDate>Sat, 07 Dec 2024 13:19:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47115</strong></p>
  <p>IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27260 – IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27260</guid>
    <pubDate>Thu, 16 May 2024 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27260</strong></p>
  <p>IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  283985.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27273 – IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27273</guid>
    <pubDate>Tue, 07 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27273</strong></p>
  <p>IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation.  IBM X-Force ID:  284903.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25021 – IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25021</guid>
    <pubDate>Thu, 22 Feb 2024 12:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25021</strong></p>
  <p>IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands.  IBM X-Force ID:  281320.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-114</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45171 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45171</guid>
    <pubDate>Thu, 11 Jan 2024 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45171</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service.  IBM X-Force ID:  267969.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45169 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45169</guid>
    <pubDate>Thu, 11 Jan 2024 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45169</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service.  IBM X-Force ID:  267967.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45175 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45175</guid>
    <pubDate>Thu, 11 Jan 2024 02:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45175</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.  IBM X-Force ID:  267973.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45173 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45173</guid>
    <pubDate>Thu, 11 Jan 2024 02:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45173</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service.  IBM X-Force ID:  267971.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45165 – IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45165</guid>
    <pubDate>Fri, 22 Dec 2023 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45165</strong></p>
  <p>IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service.  IBM X-Force ID:  267963.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45172 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45172</guid>
    <pubDate>Tue, 19 Dec 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45172</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service.  IBM X-Force ID:  267970.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45174 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45174</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45174</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to escalate privileges or cause a denial of service.  IBM X-Force ID:  267972.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45170 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45170</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45170</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command to escalate privileges or cause a denial of service.  IBM X-Force ID:  267968.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45166 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45166</guid>
    <pubDate>Wed, 13 Dec 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45166</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu command to obtain elevated privileges.  IBM X-Force ID:  267964.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45168 – IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45168</guid>
    <pubDate>Fri, 01 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45168</strong></p>
  <p>IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  267966.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45167 – IBM AIX's 7.3 Python implementation could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45167</guid>
    <pubDate>Fri, 10 Nov 2023 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45167</strong></p>
  <p>IBM AIX's 7.3 Python implementation could allow a non-privileged local user to exploit a vulnerability to cause a denial of service.  IBM X-Force ID:  267965.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40371 – IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40371</guid>
    <pubDate>Thu, 24 Aug 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40371</strong></p>
  <p>IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls.  IBM X-Force ID:  263476.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28528 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28528</guid>
    <pubDate>Fri, 28 Apr 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28528</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands.  IBM X-Force ID:  251207.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26286 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26286</guid>
    <pubDate>Wed, 26 Apr 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26286</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands.  IBM X-Force ID:  248421.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-47990 – IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47990</guid>
    <pubDate>Wed, 18 Jan 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-47990</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could result in a denial of service or arbitrary code execution. IBM X-Force ID: 243556.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43849 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43849</guid>
    <pubDate>Fri, 23 Dec 2022 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43849</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a denial of service.  IBM X-Force ID:  239170.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43848 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43848</guid>
    <pubDate>Fri, 23 Dec 2022 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43848</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.  IBM X-Force ID:  239169.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41290 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41290</guid>
    <pubDate>Fri, 23 Dec 2022 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41290</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges.  IBM X-Force ID:  236690.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39164 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39164</guid>
    <pubDate>Fri, 23 Dec 2022 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39164</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service.  IBM X-Force ID:  235181.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43381 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43381</guid>
    <pubDate>Fri, 23 Dec 2022 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43381</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-Force ID: 238639.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43380 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43380</guid>
    <pubDate>Fri, 23 Dec 2022 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43380</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a denial of service. IBM X-Force ID: 238640.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40233 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40233</guid>
    <pubDate>Fri, 23 Dec 2022 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40233</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a denial of service.  IBM X-Force ID:  235599.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39165 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39165</guid>
    <pubDate>Fri, 23 Dec 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39165</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service.  IBM X-Force ID:  235183.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43382 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43382</guid>
    <pubDate>Tue, 20 Dec 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43382</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service.  IBM X-Force ID:  238641.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36768 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36768</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36768</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34356 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34356</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34356</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22444 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22444</guid>
    <pubDate>Wed, 15 Jun 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22444</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22351 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22351</guid>
    <pubDate>Mon, 07 Mar 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22351</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38989 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38989</guid>
    <pubDate>Mon, 07 Mar 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38989</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38988 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38988</guid>
    <pubDate>Mon, 07 Mar 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38988</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22350 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22350</guid>
    <pubDate>Wed, 02 Mar 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22350</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38996 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38996</guid>
    <pubDate>Wed, 02 Mar 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38996</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38955 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38955</guid>
    <pubDate>Tue, 01 Mar 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38955</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38993 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38993</guid>
    <pubDate>Fri, 25 Feb 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38993</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38995 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38995</guid>
    <pubDate>Thu, 24 Feb 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38995</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38994 – IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38994</guid>
    <pubDate>Thu, 24 Feb 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38994</strong></p>
  <p>IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38991 – IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38991</guid>
    <pubDate>Tue, 11 Jan 2022 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38991</strong></p>
  <p>IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38990 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38990</guid>
    <pubDate>Mon, 10 Jan 2022 14:10:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38990</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29861 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29861</guid>
    <pubDate>Wed, 17 Nov 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29861</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29860 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29860</guid>
    <pubDate>Wed, 17 Nov 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29860</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive information. IBM X-Force ID: 206084.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29862 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29862</guid>
    <pubDate>Thu, 26 Aug 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29862</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 206086.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29801 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29801</guid>
    <pubDate>Thu, 26 Aug 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29801</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain root privileges. IBM X-Force ID: 203977.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29727 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29727</guid>
    <pubDate>Thu, 26 Aug 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29727</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29741 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29741</guid>
    <pubDate>Mon, 02 Aug 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29741</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29693 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29693</guid>
    <pubDate>Mon, 28 Jun 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29693</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29706 – IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29706</guid>
    <pubDate>Thu, 17 Jun 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29706</strong></p>
  <p>IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4887 – IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4887</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4887</strong></p>
  <p>IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to create arbitrary files in any directory. IBM X-Force ID: 190911.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4829 – IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4829</guid>
    <pubDate>Thu, 10 Dec 2020 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4829</strong></p>
  <p>IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1655 – IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1655</guid>
    <pubDate>Fri, 22 Jun 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1655</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1692 – IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1692</guid>
    <pubDate>Wed, 07 Feb 2018 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1692</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8972 – IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8972</guid>
    <pubDate>Wed, 15 Feb 2017 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8972</strong></p>
  <p>IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-8944 – IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8944</guid>
    <pubDate>Wed, 15 Feb 2017 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-8944</strong></p>
  <p>IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6079 – IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6079</guid>
    <pubDate>Wed, 15 Feb 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6079</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1093 – IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1093</guid>
    <pubDate>Thu, 02 Feb 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1093</strong></p>
  <p>IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3053 – IBM AIX contains an unspecified vulnerability that would allow a locally authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3053</guid>
    <pubDate>Wed, 01 Feb 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3053</strong></p>
  <p>IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2016-0281 – The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0281</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2016-0281</strong></p>
  <p>The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2016-0266 – IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0266</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2016-0266</strong></p>
  <p>IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-4948 – netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4948</guid>
    <pubDate>Fri, 16 Oct 2015 01:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-4948</strong></p>
  <p>netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8904 – lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8904</guid>
    <pubDate>Thu, 15 Jan 2015 22:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8904</strong></p>
  <p>lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3074 – The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3074</guid>
    <pubDate>Wed, 02 Jul 2014 10:35:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3074</strong></p>
  <p>The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3977 – libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3977</guid>
    <pubDate>Sun, 08 Jun 2014 23:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3977</strong></p>
  <p>libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0930 – The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0930</guid>
    <pubDate>Thu, 08 May 2014 10:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0930</strong></p>
  <p>The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0899 – ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partitio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0899</guid>
    <pubDate>Tue, 11 Mar 2014 13:01:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0899</strong></p>
  <p>ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-5419 – Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-5419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-5419</guid>
    <pubDate>Fri, 04 Oct 2013 10:44:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-5419</strong></p>
  <p>Multiple buffer overflows in (1) mkque and (2) mkquedev in bos.rte.printers in IBM AIX 6.1 and 7.1 allow local users to gain privileges by leveraging printq group membership.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-5419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4011 – Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4011</guid>
    <pubDate>Thu, 18 Jul 2013 16:51:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4011</strong></p>
  <p>Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3005 – The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3005</guid>
    <pubDate>Sat, 06 Jul 2013 13:57:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3005</strong></p>
  <p>The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3035 – The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3035</guid>
    <pubDate>Fri, 21 Jun 2013 14:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3035</strong></p>
  <p>The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-4845 – The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4845</guid>
    <pubDate>Sat, 20 Oct 2012 10:41:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-4845</strong></p>
  <p>The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-4833 – fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4833</guid>
    <pubDate>Mon, 01 Oct 2012 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-4833</strong></p>
  <p>fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-4817 – The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4817</guid>
    <pubDate>Fri, 14 Sep 2012 23:55:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-4817</strong></p>
  <p>The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-0723 – The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0723</guid>
    <pubDate>Mon, 30 Jul 2012 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-0723</strong></p>
  <p>The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2200 – The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2200</guid>
    <pubDate>Wed, 27 Jun 2012 10:18:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2200</strong></p>
  <p>The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2179 – libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2179</guid>
    <pubDate>Fri, 22 Jun 2012 10:24:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2179</strong></p>
  <p>libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2192 – The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2192</guid>
    <pubDate>Wed, 20 Jun 2012 10:27:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2192</strong></p>
  <p>The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0745 – The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0745</guid>
    <pubDate>Fri, 04 May 2012 16:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0745</strong></p>
  <p>The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1385 – IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1385</guid>
    <pubDate>Fri, 02 Mar 2012 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1385</strong></p>
  <p>IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0194 – The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0194</guid>
    <pubDate>Mon, 06 Feb 2012 20:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0194</strong></p>
  <p>The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1384 – The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1384</guid>
    <pubDate>Wed, 04 Jan 2012 03:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1384</strong></p>
  <p>The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1375 – IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1375</guid>
    <pubDate>Fri, 11 Nov 2011 21:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1375</strong></p>
  <p>IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-3982 – The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3982</guid>
    <pubDate>Wed, 05 Oct 2011 02:56:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-3982</strong></p>
  <p>The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a deadlock in timer processing across CPUs.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1561 – The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1561</guid>
    <pubDate>Tue, 05 Apr 2011 15:19:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1561</strong></p>
  <p>The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0637 – The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unuse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0637</guid>
    <pubDate>Tue, 25 Jan 2011 01:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0637</strong></p>
  <p>The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-3406 – Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3406</guid>
    <pubDate>Thu, 16 Sep 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-3406</strong></p>
  <p>Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.</p>
  <p><strong>CVSS:</strong> 1.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-3405 – Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3405</guid>
    <pubDate>Thu, 16 Sep 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-3405</strong></p>
  <p>Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-3187 – Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3187</guid>
    <pubDate>Mon, 30 Aug 2010 20:00:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-3187</strong></p>
  <p>Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1039 – Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1039</guid>
    <pubDate>Thu, 20 May 2010 17:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1039</strong></p>
  <p>Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1039">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
