VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2004-1663Sep 4, 2004
    risk 0.00cvss epss 0.04

    Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.

  • CVE-2004-1372Sep 1, 2004
    risk 0.00cvss epss 0.00

    Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.

  • CVE-2004-0684Aug 6, 2004
    risk 0.00cvss epss 0.02

    WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

  • CVE-2004-0545Aug 6, 2004
    risk 0.00cvss epss 0.00

    LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2004-0586Aug 6, 2004
    risk 0.00cvss epss 0.04

    acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.

  • CVE-2004-0669Aug 6, 2004
    risk 0.00cvss epss 0.02

    Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.

  • CVE-2003-0257Apr 15, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

  • CVE-2003-0170Mar 29, 2004
    risk 0.00cvss epss 0.03

    Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

  • CVE-2003-1018Mar 29, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

  • CVE-2003-0119Feb 3, 2004
    risk 0.00cvss epss 0.02

    The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.

  • CVE-2004-1759Jan 21, 2004
    risk 0.00cvss epss 0.02

    Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.

  • CVE-2004-1760Jan 21, 2004
    risk 0.00cvss epss 0.04

    The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

  • CVE-2004-0029Jan 20, 2004
    risk 0.00cvss epss 0.00

    Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

  • CVE-2003-0696Jan 20, 2004
    risk 0.00cvss epss 0.01

    The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).

  • CVE-2003-1527Dec 31, 2003
    risk 0.00cvss epss 0.01

    BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

  • CVE-2003-1447Dec 31, 2003
    risk 0.00cvss epss 0.00

    IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

  • CVE-2003-1282Dec 31, 2003
    risk 0.00cvss epss 0.01

    IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that…

  • CVE-2003-0954Dec 31, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.

  • CVE-2003-0914Dec 15, 2003
    risk 0.00cvss epss 0.03

    ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

  • CVE-2003-0836Nov 17, 2003
    risk 0.00cvss epss 0.02

    Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.

  • CVE-2003-0837Nov 17, 2003
    risk 0.00cvss epss 0.02

    Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.

  • CVE-2003-0827Oct 6, 2003
    risk 0.00cvss epss 0.01

    The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.

  • CVE-2003-0784Oct 6, 2003
    risk 0.00cvss epss 0.02

    Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

  • CVE-2003-0697Oct 6, 2003
    risk 0.00cvss epss 0.00

    Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

  • CVE-2003-0580Aug 18, 2003
    risk 0.00cvss epss 0.01

    Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.

  • CVE-2003-0285Jun 16, 2003
    risk 0.00cvss epss 0.05

    IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam…

  • CVE-2003-0181Apr 2, 2003
    risk 0.00cvss epss 0.02

    Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.

  • CVE-2003-0180Apr 2, 2003
    risk 0.00cvss epss 0.03

    Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.

  • CVE-2002-1548Mar 31, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."

  • CVE-2002-1551Mar 31, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.

  • CVE-2002-1550Mar 31, 2003
    risk 0.00cvss epss 0.00

    dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2003-0123Mar 18, 2003
    risk 0.00cvss epss 0.03

    Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.

  • CVE-2003-0064Mar 3, 2003
    risk 0.00cvss epss 0.03

    The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker…

  • CVE-2002-2372Dec 31, 2002
    risk 0.00cvss epss 0.02

    The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.

  • CVE-2002-1624Dec 31, 2002
    risk 0.00cvss epss 0.04

    Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.

  • CVE-2002-2025Dec 31, 2002
    risk 0.00cvss epss 0.02

    Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to…

  • CVE-2002-1622Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."

  • CVE-2002-2014Dec 31, 2002
    risk 0.00cvss epss 0.02

    Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.

  • CVE-2002-1689Dec 31, 2002
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

  • CVE-2002-1687Dec 31, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.

  • CVE-2002-1822Dec 31, 2002
    risk 0.00cvss epss 0.02

    IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).

  • CVE-2002-1690Dec 31, 2002
    risk 0.00cvss epss 0.01

    Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

  • CVE-2002-1686Dec 31, 2002
    risk 0.00cvss epss 0.01

    Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

  • CVE-2002-1654Dec 31, 2002
    risk 0.00cvss epss 0.03

    iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force…

  • CVE-2002-1201Oct 28, 2002
    risk 0.00cvss epss 0.02

    IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

  • CVE-2002-1203Oct 28, 2002
    risk 0.00cvss epss 0.02

    IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.

  • CVE-2002-1153Oct 11, 2002
    risk 0.00cvss epss 0.03

    IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".

  • CVE-2002-1012Oct 4, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.

  • CVE-2002-1041Oct 4, 2002
    risk 0.00cvss epss 0.01

    Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.

  • CVE-2002-1040Oct 4, 2002
    risk 0.00cvss epss 0.01

    Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.

Page 174 of 177