Vendor CVEs
IBM
All CVEs
8,825 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-1663 | 0.00 | — | 0.04 | Sep 4, 2004 | Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets. | |||
| CVE-2004-1372 | 0.00 | — | 0.00 | Sep 1, 2004 | Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure. | |||
| CVE-2004-0684 | 0.00 | — | 0.02 | Aug 6, 2004 | WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters. | |||
| CVE-2004-0545 | 0.00 | — | 0.00 | Aug 6, 2004 | LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2004-0586 | 0.00 | — | 0.04 | Aug 6, 2004 | acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods. | |||
| CVE-2004-0669 | 0.00 | — | 0.02 | Aug 6, 2004 | Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command. | |||
| CVE-2003-0257 | 0.00 | — | 0.00 | Apr 15, 2004 | Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges. | |||
| CVE-2003-0170 | 0.00 | — | 0.03 | Mar 29, 2004 | Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors. | |||
| CVE-2003-1018 | 0.00 | — | 0.00 | Mar 29, 2004 | Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors. | |||
| CVE-2003-0119 | 0.00 | — | 0.02 | Feb 3, 2004 | The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities. | |||
| CVE-2004-1759 | 0.00 | — | 0.02 | Jan 21, 2004 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |||
| CVE-2004-1760 | 0.00 | — | 0.04 | Jan 21, 2004 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |||
| CVE-2004-0029 | 0.00 | — | 0.00 | Jan 20, 2004 | Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges. | |||
| CVE-2003-0696 | 0.00 | — | 0.01 | Jan 20, 2004 | The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion). | |||
| CVE-2003-1527 | 0.00 | — | 0.01 | Dec 31, 2003 | BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. | |||
| CVE-2003-1447 | 0.00 | — | 0.00 | Dec 31, 2003 | IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML. | |||
| CVE-2003-1282 | 0.00 | — | 0.01 | Dec 31, 2003 | IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that… | |||
| CVE-2003-0954 | 0.00 | — | 0.00 | Dec 31, 2003 | Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges. | |||
| CVE-2003-0914 | 0.00 | — | 0.03 | Dec 15, 2003 | ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value. | |||
| CVE-2003-0836 | 0.00 | — | 0.02 | Nov 17, 2003 | Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command. | |||
| CVE-2003-0837 | 0.00 | — | 0.02 | Nov 17, 2003 | Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command. | |||
| CVE-2003-0827 | 0.00 | — | 0.01 | Oct 6, 2003 | The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523. | |||
| CVE-2003-0784 | 0.00 | — | 0.02 | Oct 6, 2003 | Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers. | |||
| CVE-2003-0697 | 0.00 | — | 0.00 | Oct 6, 2003 | Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges. | |||
| CVE-2003-0580 | 0.00 | — | 0.01 | Aug 18, 2003 | Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument. | |||
| CVE-2003-0285 | 0.00 | — | 0.05 | Jun 16, 2003 | IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam… | |||
| CVE-2003-0181 | 0.00 | — | 0.02 | Apr 2, 2003 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name. | |||
| CVE-2003-0180 | 0.00 | — | 0.03 | Apr 2, 2003 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form. | |||
| CVE-2002-1548 | 0.00 | — | 0.00 | Mar 31, 2003 | Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called." | |||
| CVE-2002-1551 | 0.00 | — | 0.00 | Mar 31, 2003 | Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code. | |||
| CVE-2002-1550 | 0.00 | — | 0.00 | Mar 31, 2003 | dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |||
| CVE-2003-0123 | 0.00 | — | 0.03 | Mar 18, 2003 | Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line. | |||
| CVE-2003-0064 | 0.00 | — | 0.03 | Mar 3, 2003 | The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker… | |||
| CVE-2002-2372 | 0.00 | — | 0.02 | Dec 31, 2002 | The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow. | |||
| CVE-2002-1624 | 0.00 | — | 0.04 | Dec 31, 2002 | Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters. | |||
| CVE-2002-2025 | 0.00 | — | 0.02 | Dec 31, 2002 | Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to… | |||
| CVE-2002-1622 | 0.00 | — | 0.03 | Dec 31, 2002 | Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type." | |||
| CVE-2002-2014 | 0.00 | — | 0.02 | Dec 31, 2002 | Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks. | |||
| CVE-2002-1689 | 0.00 | — | 0.02 | Dec 31, 2002 | Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. | |||
| CVE-2002-1687 | 0.00 | — | 0.00 | Dec 31, 2002 | Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable. | |||
| CVE-2002-1822 | 0.00 | — | 0.02 | Dec 31, 2002 | IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP). | |||
| CVE-2002-1690 | 0.00 | — | 0.01 | Dec 31, 2002 | Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225. | |||
| CVE-2002-1686 | 0.00 | — | 0.01 | Dec 31, 2002 | Buffer overflow in lscfg of unknown versions of AIX has unknown impact. | |||
| CVE-2002-1654 | 0.00 | — | 0.03 | Dec 31, 2002 | iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force… | |||
| CVE-2002-1201 | 0.00 | — | 0.02 | Oct 28, 2002 | IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers. | |||
| CVE-2002-1203 | 0.00 | — | 0.02 | Oct 28, 2002 | IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set. | |||
| CVE-2002-1153 | 0.00 | — | 0.03 | Oct 11, 2002 | IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host". | |||
| CVE-2002-1012 | 0.00 | — | 0.03 | Oct 4, 2002 | Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. | |||
| CVE-2002-1041 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. | |||
| CVE-2002-1040 | 0.00 | — | 0.01 | Oct 4, 2002 | Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. |
- CVE-2004-1663Sep 4, 2004risk 0.00cvss —epss 0.04
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
- CVE-2004-1372Sep 1, 2004risk 0.00cvss —epss 0.00
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
- CVE-2004-0684Aug 6, 2004risk 0.00cvss —epss 0.02
WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.
- CVE-2004-0545Aug 6, 2004risk 0.00cvss —epss 0.00
LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2004-0586Aug 6, 2004risk 0.00cvss —epss 0.04
acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.
- CVE-2004-0669Aug 6, 2004risk 0.00cvss —epss 0.02
Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
- CVE-2003-0257Apr 15, 2004risk 0.00cvss —epss 0.00
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
- CVE-2003-0170Mar 29, 2004risk 0.00cvss —epss 0.03
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
- CVE-2003-1018Mar 29, 2004risk 0.00cvss —epss 0.00
Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.
- CVE-2003-0119Feb 3, 2004risk 0.00cvss —epss 0.02
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
- CVE-2004-1759Jan 21, 2004risk 0.00cvss —epss 0.02
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
- CVE-2004-1760Jan 21, 2004risk 0.00cvss —epss 0.04
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
- CVE-2004-0029Jan 20, 2004risk 0.00cvss —epss 0.00
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
- CVE-2003-0696Jan 20, 2004risk 0.00cvss —epss 0.01
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).
- CVE-2003-1527Dec 31, 2003risk 0.00cvss —epss 0.01
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
- CVE-2003-1447Dec 31, 2003risk 0.00cvss —epss 0.00
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
- CVE-2003-1282Dec 31, 2003risk 0.00cvss —epss 0.01
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that…
- CVE-2003-0954Dec 31, 2003risk 0.00cvss —epss 0.00
Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
- CVE-2003-0914Dec 15, 2003risk 0.00cvss —epss 0.03
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
- CVE-2003-0836Nov 17, 2003risk 0.00cvss —epss 0.02
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.
- CVE-2003-0837Nov 17, 2003risk 0.00cvss —epss 0.02
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
- CVE-2003-0827Oct 6, 2003risk 0.00cvss —epss 0.01
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
- CVE-2003-0784Oct 6, 2003risk 0.00cvss —epss 0.02
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
- CVE-2003-0697Oct 6, 2003risk 0.00cvss —epss 0.00
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
- CVE-2003-0580Aug 18, 2003risk 0.00cvss —epss 0.01
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.
- CVE-2003-0285Jun 16, 2003risk 0.00cvss —epss 0.05
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam…
- CVE-2003-0181Apr 2, 2003risk 0.00cvss —epss 0.02
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
- CVE-2003-0180Apr 2, 2003risk 0.00cvss —epss 0.03
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.
- CVE-2002-1548Mar 31, 2003risk 0.00cvss —epss 0.00
Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."
- CVE-2002-1551Mar 31, 2003risk 0.00cvss —epss 0.00
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
- CVE-2002-1550Mar 31, 2003risk 0.00cvss —epss 0.00
dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2003-0123Mar 18, 2003risk 0.00cvss —epss 0.03
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
- CVE-2003-0064Mar 3, 2003risk 0.00cvss —epss 0.03
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker…
- CVE-2002-2372Dec 31, 2002risk 0.00cvss —epss 0.02
The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.
- CVE-2002-1624Dec 31, 2002risk 0.00cvss —epss 0.04
Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
- CVE-2002-2025Dec 31, 2002risk 0.00cvss —epss 0.02
Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to…
- CVE-2002-1622Dec 31, 2002risk 0.00cvss —epss 0.03
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
- CVE-2002-2014Dec 31, 2002risk 0.00cvss —epss 0.02
Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.
- CVE-2002-1689Dec 31, 2002risk 0.00cvss —epss 0.02
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
- CVE-2002-1687Dec 31, 2002risk 0.00cvss —epss 0.00
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
- CVE-2002-1822Dec 31, 2002risk 0.00cvss —epss 0.02
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
- CVE-2002-1690Dec 31, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
- CVE-2002-1686Dec 31, 2002risk 0.00cvss —epss 0.01
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
- CVE-2002-1654Dec 31, 2002risk 0.00cvss —epss 0.03
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force…
- CVE-2002-1201Oct 28, 2002risk 0.00cvss —epss 0.02
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
- CVE-2002-1203Oct 28, 2002risk 0.00cvss —epss 0.02
IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.
- CVE-2002-1153Oct 11, 2002risk 0.00cvss —epss 0.03
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
- CVE-2002-1012Oct 4, 2002risk 0.00cvss —epss 0.03
Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
- CVE-2002-1041Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
- CVE-2002-1040Oct 4, 2002risk 0.00cvss —epss 0.01
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
Page 174 of 177