Vios

Vendor:

First CVE: Oct 15, 2009 · Active for 16 years

92
Total CVEs
More Total CVEs than 99% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 15, 2009
16 years ago
Most Recent CVE
Apr 23, 2026
93 days ago

CVE Severity & Scoring

Vios92 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local60 (65.2%)
Network11 (12.0%)
Unknown21 (22.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (68.5%)
High8 (8.7%)
Unknown21 (22.8%)
User Interaction
None70 (76.1%)
Unknown21 (22.8%)
Required1 (1.1%)
Privileges Required
Low43 (46.7%)
High3 (3.3%)
None25 (27.2%)
Unknown21 (22.8%)

Top CVEs

Signals from CVEs in this product scope (92 CVEs).

92 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to
Oct 15, 200910.079NOYES
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B
May 20, 201010.053NOYES
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV910
Feb 15, 20177.836NOYES
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1
Jul 18, 20137.236NOYES
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. T
Nov 13, 20259.835NONO
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improp
Nov 13, 20259.835NONO
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV8
Feb 15, 20177.835NOYES
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 2512
Apr 28, 20237.834NOYES
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An a
Nov 13, 20259.131NONO

Exploit Exposure

Signals from CVEs in this product scope (92 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
4.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
7.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (92 CVEs).

Media Mentions

Signals from CVEs in this product scope (92 CVEs).

Top CNAs Publishing CVEs For Vios

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.2.075.40.4%00
4.1.118.40.2%00
4.1.049.20.5%00
4.186.80.2%00
3.1.214.70.4%00
3.1.114.70.4%00
3.1.077.70.4%00
3.1466.50.3%01
2.2.5.1027.81.9%02
2.2.5.027.81.9%02
2.2.4.3027.81.9%02
2.2.4.2327.81.9%02
2.2.4.2236.41.8%02
2.2.4.2136.41.8%02
2.2.4.1036.41.8%02
2.2.4.036.41.8%02
2.2.3.8027.81.9%02
2.2.3.7036.41.8%02
2.2.3.6036.41.8%02
2.2.3.5236.41.8%02