VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2000-1119Jan 9, 2001
    risk 0.03cvss epss 0.01

    Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.

  • CVE-2000-1120Jan 9, 2001
    risk 0.03cvss epss 0.01

    Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.

  • CVE-2000-0873Nov 14, 2000
    risk 0.03cvss epss 0.01

    netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

  • CVE-1999-0693Mar 2, 2000
    risk 0.03cvss epss 0.01

    Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

  • CVE-1999-1488Dec 31, 1999
    risk 0.03cvss epss 0.04

    sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.

  • CVE-1999-1117Dec 31, 1999
    risk 0.03cvss epss 0.01

    lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

  • CVE-2000-0027Dec 27, 1999
    risk 0.03cvss epss 0.01

    IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

  • CVE-1999-1531Nov 2, 1999
    risk 0.03cvss epss 0.05

    Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.

  • CVE-1999-0944Oct 24, 1999
    risk 0.03cvss epss 0.04

    IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.

  • CVE-1999-0789Sep 28, 1999
    risk 0.03cvss epss 0.03

    Buffer overflow in AIX ftpd in the libc library.

  • CVE-1999-0691Sep 13, 1999
    risk 0.03cvss epss 0.01

    Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

  • CVE-1999-0745Aug 18, 1999
    risk 0.03cvss epss 0.03

    Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.

  • CVE-1999-0803May 25, 1999
    risk 0.03cvss epss 0.01

    The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.

  • CVE-1999-1414May 25, 1999
    risk 0.03cvss epss 0.01

    IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

  • CVE-1999-1405Feb 17, 1999
    risk 0.03cvss epss 0.03

    snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd…

  • CVE-1999-0118Nov 1, 1998
    risk 0.03cvss epss 0.01

    AIX infod allows local users to gain root access through an X display.

  • CVE-1999-0014Jan 21, 1998
    risk 0.03cvss epss 0.01

    Unauthorized privileged access or denial of service via dtappgather program in CDE.

  • CVE-1999-0092Oct 29, 1997
    risk 0.03cvss epss 0.01

    Various vulnerabilities in the AIX portmir command allows local users to obtain root access.

  • CVE-1999-0115Sep 1, 1997
    risk 0.03cvss epss 0.01

    AIX bugfiler program allows local users to gain root access.

  • CVE-1999-0122Jul 21, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in AIX lchangelv gives root access.

  • CVE-1999-1208Jul 21, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.

  • CVE-1999-0064May 26, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in AIX lquerylv program gives root access to local users.

  • CVE-1999-0112May 1, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in AIX dtterm program for the CDE.

  • CVE-1999-0040May 1, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

  • CVE-1999-1408Mar 5, 1997
    risk 0.03cvss epss 0.01

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

  • CVE-1999-0130Nov 16, 1996
    risk 0.03cvss epss 0.01

    Local users can start Sendmail in daemon mode and gain root privileges.

  • CVE-1999-0116Sep 19, 1996
    risk 0.03cvss epss 0.06

    Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

  • CVE-1999-0023Jul 24, 1996
    risk 0.03cvss epss 0.01

    Local user gains root privileges via buffer overflow in rdist, via lookup() function.

  • CVE-2015-1923Jun 30, 2015
    risk 0.02cvss epss 0.19

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

  • CVE-2015-1896May 25, 2015
    risk 0.02cvss epss 0.32

    Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2008-4563Mar 11, 2009
    risk 0.02cvss epss 0.29

    Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute…

  • CVE-2007-5909Nov 10, 2007
    risk 0.02cvss epss 0.21

    Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary…

  • CVE-2007-2582May 10, 2007
    risk 0.02cvss epss 0.27

    Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2)…

  • CVE-2006-5855Dec 6, 2006
    risk 0.02cvss epss 0.27

    Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte,…

  • CVE-2002-0679Sep 5, 2002
    risk 0.02cvss epss 0.23

    Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

  • CVE-2015-4947Sep 15, 2015
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to…

  • CVE-2015-4935Aug 3, 2015
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4934.

  • CVE-2015-4934Aug 3, 2015
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4935.

  • CVE-2015-4933Aug 3, 2015
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

  • CVE-2015-4932Aug 3, 2015
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

  • CVE-2015-4931Aug 3, 2015
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4932, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

  • CVE-2015-1986Jun 30, 2015
    risk 0.01cvss epss 0.08

    The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.

  • CVE-2015-1942Jun 30, 2015
    risk 0.01cvss epss 0.07

    The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute these files, via a crafted TCP packet to an unspecified port.

  • CVE-2015-1903May 20, 2015
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSN3Y.

  • CVE-2015-1902May 20, 2015
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSMLA.

  • CVE-2015-1920May 20, 2015
    risk 0.01cvss epss 0.07

    IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.

  • CVE-2014-8891Mar 6, 2015
    risk 0.01cvss epss 0.07

    Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code…

  • CVE-2014-6140Dec 6, 2014
    risk 0.01cvss epss 0.06

    IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and…

  • CVE-2014-2421Apr 16, 2014
    risk 0.01cvss epss 0.07

    Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

  • CVE-2014-0457Apr 16, 2014
    risk 0.01cvss epss 0.07

    Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

Page 127 of 177