IBM
IBM AIX: vulnerabilidades y CVE
IBM AIX tiene 551 vulnerabilidades publicadas, 156 de ellas en los últimos 12 meses. 49 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE551
Últimos 12 meses156
Críticas49
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16821 | Alta (7.8) | 0.10% | — | 28 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. |
| CVE-2026-19783 | Alta (7.8) | 0.11% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write… |
| CVE-2026-19449 | Alta (8.8) | 0.14% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. |
| CVE-2026-19448 | Alta (7.5) | 0.25% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash,… |
| CVE-2026-19446 | Alta (7.5) | 1.0% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart. |
| CVE-2026-19442 | Alta (8.8) | 0.12% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full… |
| CVE-2026-19437 | Crítica (9.8) | 0.47% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. |
| CVE-2026-18842 | Alta (7.8) | 0.12% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write. |
| CVE-2026-18840 | Alta (7.8) | 0.12% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer. |
| CVE-2026-18835 | Crítica (9.9) | 0.79% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-18832 | Crítica (9.8) | 0.59% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. |
| CVE-2026-18828 | Alta (7.5) | 0.37% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. |
| CVE-2026-18824 | Alta (8.8) | 0.41% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-18822 | Media (5.5) | 0.10% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records. |
| CVE-2026-18716 | Crítica (9.1) | 0.29% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. |
| CVE-2026-18670 | Crítica (9.1) | 0.38% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. |
| CVE-2026-17436 | Crítica (9.8) | 0.59% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. |
| CVE-2026-17425 | Alta (7.5) | 0.55% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow. |
| CVE-2026-17424 | Media (6.5) | 0.27% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-17423 | Crítica (9.1) | 0.33% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read. |
| CVE-2026-17422 | Alta (8.8) | 0.13% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. |
| CVE-2026-17195 | Media (6.5) | 0.13% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write. |
| CVE-2026-17171 | Alta (7.8) | 0.17% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links. |
| CVE-2026-17170 | Alta (7.5) | 0.55% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size. |
| CVE-2026-17168 | Alta (8.8) | 0.45% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. |
| CVE-2026-17165 | Alta (7.5) | 0.55% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. |
| CVE-2026-17163 | Alta (7.5) | 0.55% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field. |
| CVE-2026-17160 | Crítica (9.8) | 0.80% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation. |
| CVE-2026-17159 | Alta (7.5) | 0.55% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow. |
| CVE-2026-17157 | Crítica (9.8) | 0.80% | — | 20 ago 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. |
Otros productos de IBM
Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142Rational Collaborative Lifecycle Management · 141