VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2007-3263Jun 19, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."

  • CVE-2007-3262Jun 19, 2007
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant…

  • CVE-2007-3128Jun 19, 2007
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2007-3232Jun 15, 2007
    risk 0.00cvss epss 0.03

    The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard…

  • CVE-2007-0068Jun 6, 2007
    risk 0.00cvss epss 0.02

    IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.

  • CVE-2007-2996Jun 4, 2007
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships…

  • CVE-2007-2995Jun 4, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors.

  • CVE-2007-2690May 16, 2007
    risk 0.00cvss epss 0.02

    Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.

  • CVE-2006-7198Apr 30, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.

  • CVE-2007-1944Apr 11, 2007
    risk 0.00cvss epss 0.02

    The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

  • CVE-2007-1941Apr 11, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different…

  • CVE-2007-1945Apr 11, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.

  • CVE-2007-1940Apr 11, 2007
    risk 0.00cvss epss 0.00

    IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.

  • CVE-2007-1798Apr 2, 2007
    risk 0.00cvss epss 0.00

    Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.

  • CVE-2007-1784Mar 31, 2007
    risk 0.00cvss epss 0.03

    The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.

  • CVE-2006-4843Mar 29, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.

  • CVE-2007-1739Mar 28, 2007
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory…

  • CVE-2007-1608Mar 22, 2007
    risk 0.00cvss epss 0.02

    CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.

  • CVE-2006-7165Mar 20, 2007
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."

  • CVE-2006-7166Mar 20, 2007
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."

  • CVE-2006-7164Mar 20, 2007
    risk 0.00cvss epss 0.01

    SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

  • CVE-2007-1468Mar 16, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.

  • CVE-2007-1228Mar 2, 2007
    risk 0.00cvss epss 0.00

    IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.

  • CVE-2007-1087Feb 23, 2007
    risk 0.00cvss epss 0.01

    IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

  • CVE-2007-1088Feb 23, 2007
    risk 0.00cvss epss 0.01

    Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.

  • CVE-2007-1089Feb 23, 2007
    risk 0.00cvss epss 0.00

    IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

  • CVE-2007-1086Feb 23, 2007
    risk 0.00cvss epss 0.00

    Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."

  • CVE-2007-1027Feb 21, 2007
    risk 0.00cvss epss 0.00

    Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.

  • CVE-2007-0978Feb 16, 2007
    risk 0.00cvss epss 0.00

    Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

  • CVE-2007-0670Feb 3, 2007
    risk 0.00cvss epss 0.00

    Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.

  • CVE-2007-0618Jan 31, 2007
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."

  • CVE-2007-0442Jan 23, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.

  • CVE-2007-0392Jan 19, 2007
    risk 0.00cvss epss 0.00

    IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.

  • CVE-2006-6914Dec 31, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.

  • CVE-2006-6915Dec 31, 2006
    risk 0.00cvss epss 0.01

    ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.

  • CVE-2006-6836Dec 31, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.

  • CVE-2006-6636Dec 19, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.

  • CVE-2006-6638Dec 19, 2006
    risk 0.00cvss epss 0.02

    IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.

  • CVE-2006-6637Dec 19, 2006
    risk 0.00cvss epss 0.03

    The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific…

  • CVE-2006-6607Dec 18, 2006
    risk 0.00cvss epss 0.01

    The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command line argument, which allows local users to obtain the password by listing the process or using other…

  • CVE-2006-6537Dec 14, 2006
    risk 0.00cvss epss 0.02

    IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.

  • CVE-2006-6309Dec 6, 2006
    risk 0.00cvss epss 0.02

    Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value in unspecified messages, a different issue than…

  • CVE-2006-6135Nov 28, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).

  • CVE-2006-6136Nov 28, 2006
    risk 0.00cvss epss 0.02

    IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.

  • CVE-2006-5818Nov 8, 2006
    risk 0.00cvss epss 0.00

    Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.

  • CVE-2006-5664Nov 3, 2006
    risk 0.00cvss epss 0.00

    The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.

  • CVE-2006-5663Nov 3, 2006
    risk 0.00cvss epss 0.00

    IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 use insecure permissions for installation scripts, which allows local users to gain privileges by modifying the scripts.

  • CVE-2006-5323Oct 17, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.

  • CVE-2006-5324Oct 17, 2006
    risk 0.00cvss epss 0.02

    The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.

  • CVE-2006-5163Oct 5, 2006
    risk 0.00cvss epss 0.00

    IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.

Page 170 of 177