VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2006-1246Mar 17, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.

  • CVE-2006-1210Mar 14, 2006
    risk 0.00cvss epss 0.02

    The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source. NOTE: IBM has privately confirmed to CVE that a fix is…

  • CVE-2006-1211Mar 14, 2006
    risk 0.00cvss epss 0.01

    IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions. …

  • CVE-2006-0667Mar 10, 2006
    risk 0.00cvss epss 0.00

    lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.

  • CVE-2006-1093Mar 9, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.

  • CVE-2006-0838Feb 22, 2006
    risk 0.00cvss epss 0.00

    IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges. NOTE: IBM has…

  • CVE-2006-0837Feb 22, 2006
    risk 0.00cvss epss 0.00

    IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords. NOTE:…

  • CVE-2006-0666Feb 15, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.

  • CVE-2006-0674Feb 13, 2006
    risk 0.00cvss epss 0.00

    Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.

  • CVE-2006-0662Feb 13, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.

  • CVE-2006-0580Feb 8, 2006
    risk 0.00cvss epss 0.03

    IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).

  • CVE-2006-0120Jan 9, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact…

  • CVE-2006-0119Jan 9, 2006
    risk 0.00cvss epss 0.04

    Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4)…

  • CVE-2006-0121Jan 9, 2006
    risk 0.00cvss epss 0.02

    Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the…

  • CVE-2006-0117Jan 9, 2006
    risk 0.00cvss epss 0.02

    Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".

  • CVE-2006-0118Jan 9, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.

  • CVE-2005-2712Dec 31, 2005
    risk 0.00cvss epss 0.03

    The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.

  • CVE-2005-2454Dec 31, 2005
    risk 0.00cvss epss 0.00

    IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.

  • CVE-2005-2619Dec 31, 2005
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the…

  • CVE-2005-4833Dec 31, 2005
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of…

  • CVE-2005-4738Dec 31, 2005
    risk 0.00cvss epss 0.01

    IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.

  • CVE-2005-4819Dec 31, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-4870Dec 31, 2005
    risk 0.00cvss epss 0.03

    Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be…

  • CVE-2005-4735Dec 31, 2005
    risk 0.00cvss epss 0.02

    IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka…

  • CVE-2005-4739Dec 31, 2005
    risk 0.00cvss epss 0.01

    IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.

  • CVE-2005-4740Dec 31, 2005
    risk 0.00cvss epss 0.01

    IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by "connecting from a downlevel client."

  • CVE-2005-4867Dec 31, 2005
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.

  • CVE-2005-4736Dec 31, 2005
    risk 0.00cvss epss 0.02

    IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.

  • CVE-2005-4737Dec 31, 2005
    risk 0.00cvss epss 0.02

    IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.

  • CVE-2005-4864Dec 31, 2005
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.

  • CVE-2005-4865Dec 31, 2005
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.

  • CVE-2005-4863Dec 31, 2005
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.

  • CVE-2005-4834Dec 31, 2005
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.

  • CVE-2005-4871Dec 31, 2005
    risk 0.00cvss epss 0.01

    Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.

  • CVE-2005-4866Dec 31, 2005
    risk 0.00cvss epss 0.02

    Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which…

  • CVE-2005-4413Dec 20, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b)…

  • CVE-2005-4273Dec 15, 2005
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.

  • CVE-2005-4271Dec 15, 2005
    risk 0.00cvss epss 0.00

    Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.

  • CVE-2005-4068Dec 8, 2005
    risk 0.00cvss epss 0.00

    Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

  • CVE-2005-3760Nov 22, 2005
    risk 0.00cvss epss 0.01

    Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).

  • CVE-2005-3749Nov 22, 2005
    risk 0.00cvss epss 0.00

    Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.

  • CVE-2005-3642Nov 16, 2005
    risk 0.00cvss epss 0.01

    IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.

  • CVE-2005-3643Nov 16, 2005
    risk 0.00cvss epss 0.01

    IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.

  • CVE-2005-3568Nov 16, 2005
    risk 0.00cvss epss 0.00

    db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."

  • CVE-2005-3569Nov 16, 2005
    risk 0.00cvss epss 0.01

    INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.

  • CVE-2005-3567Nov 16, 2005
    risk 0.00cvss epss 0.01

    slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.

  • CVE-2005-3504Nov 5, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.

  • CVE-2005-3396Nov 1, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.

  • CVE-2005-3289Oct 23, 2005
    risk 0.00cvss epss 0.00

    LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.

  • CVE-2005-3060Sep 30, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.

Page 172 of 177