VYPR

IBM i

by IBM

CVEs (15)

  • CVE-2026-18221HigSep 4, 2026
    risk 0.53cvss 8.1epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

  • CVE-2026-17273MedSep 4, 2026
    risk 0.42cvss 6.5epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

  • CVE-2026-17207MedSep 4, 2026
    risk 0.42cvss 6.5epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.

  • CVE-2026-17057MedSep 4, 2026
    risk 0.42cvss 6.5epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

  • CVE-2026-18341MedSep 4, 2026
    risk 0.41cvss 6.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

  • CVE-2026-17274MedSep 4, 2026
    risk 0.35cvss 5.4epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

  • CVE-2026-17470MedSep 4, 2026
    risk 0.34cvss 5.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

  • CVE-2026-16826MedSep 4, 2026
    risk 0.34cvss 5.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-18073MedSep 4, 2026
    risk 0.29cvss 4.4epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.

  • CVE-2026-17499MedSep 4, 2026
    risk 0.29cvss 4.4epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16693MedSep 4, 2026
    risk 0.29cvss 4.4epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

  • CVE-2026-18076MedSep 4, 2026
    risk 0.28cvss 4.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.

  • CVE-2026-17270MedSep 4, 2026
    risk 0.28cvss 4.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.

  • CVE-2026-17259MedSep 4, 2026
    risk 0.28cvss 4.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

  • CVE-2026-17255MedSep 4, 2026
    risk 0.28cvss 4.3epss

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.