VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2001-0472Jun 27, 2001
    risk 0.00cvss epss 0.01

    Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.

  • CVE-2001-0446Jun 18, 2001
    risk 0.00cvss epss 0.01

    IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

  • CVE-2001-1330Jun 11, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

  • CVE-2001-1329Jun 11, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

  • CVE-2001-0312Jun 2, 2001
    risk 0.00cvss epss 0.02

    IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

  • CVE-1999-0729Mar 12, 2001
    risk 0.00cvss epss 0.02

    Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.

  • CVE-2000-1123Jan 9, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.

  • CVE-2000-1138Jan 9, 2001
    risk 0.00cvss epss 0.01

    Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.

  • CVE-2000-1122Jan 9, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.

  • CVE-2000-1168Jan 9, 2001
    risk 0.00cvss epss 0.02

    IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

  • CVE-2000-1117Jan 9, 2001
    risk 0.00cvss epss 0.03

    The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.

  • CVE-2000-1239Dec 31, 2000
    risk 0.00cvss epss 0.02

    The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified…

  • CVE-2000-1038Dec 11, 2000
    risk 0.00cvss epss 0.02

    The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.

  • CVE-2000-1222Dec 10, 2000
    risk 0.00cvss epss 0.00

    AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.

  • CVE-2000-0761Oct 20, 2000
    risk 0.00cvss epss 0.02

    OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.

  • CVE-2000-0677Oct 20, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.

  • CVE-2000-0466Jun 20, 2000
    risk 0.00cvss epss 0.00

    AIX cdmount allows local users to gain root privileges via shell metacharacters.

  • CVE-2000-0441May 24, 2000
    risk 0.00cvss epss 0.01

    Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.

  • CVE-2000-0249Apr 26, 2000
    risk 0.00cvss epss 0.00

    The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

  • CVE-2000-1216Jan 27, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.

  • CVE-2000-0080Jan 10, 2000
    risk 0.00cvss epss 0.00

    AIX techlibss allows local users to overwrite files via a symlink attack.

  • CVE-1999-1589Dec 31, 1999
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.

  • CVE-1999-0852Dec 2, 1999
    risk 0.00cvss epss 0.00

    IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.

  • CVE-1999-0835Nov 10, 1999
    risk 0.00cvss epss 0.01

    Denial of service in BIND named via malformed SIG records.

  • CVE-1999-0851Nov 10, 1999
    risk 0.00cvss epss 0.00

    Denial of service in BIND named via naptr.

  • CVE-1999-0903Oct 26, 1999
    risk 0.00cvss epss 0.01

    genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.

  • CVE-1999-1583Sep 30, 1999
    risk 0.00cvss epss 0.01

    Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.

  • CVE-1999-1013Sep 23, 1999
    risk 0.00cvss epss 0.00

    named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.

  • CVE-1999-0687Sep 13, 1999
    risk 0.00cvss epss 0.02

    The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

  • CVE-1999-0694Aug 11, 1999
    risk 0.00cvss epss 0.00

    Denial of service in AIX ptrace system call allows local users to crash the system.

  • CVE-1999-1079May 6, 1999
    risk 0.00cvss epss 0.00

    Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

  • CVE-1999-0429Mar 1, 1999
    risk 0.00cvss epss 0.01

    The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.

  • CVE-1999-1546Jan 29, 1999
    risk 0.00cvss epss 0.01

    netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

  • CVE-1999-0088Oct 26, 1998
    risk 0.00cvss epss 0.04

    IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.

  • CVE-1999-1403Oct 2, 1998
    risk 0.00cvss epss 0.00

    IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.

  • CVE-1999-1404Oct 2, 1998
    risk 0.00cvss epss 0.01

    IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

  • CVE-1999-1574Jul 6, 1998
    risk 0.00cvss epss 0.03

    Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."

  • CVE-1999-1480Jun 11, 1998
    risk 0.00cvss epss 0.00

    (1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.

  • CVE-1999-0055May 14, 1998
    risk 0.00cvss epss 0.00

    Buffer overflows in Sun libnsl allow root access.

  • CVE-1999-0010Apr 8, 1998
    risk 0.00cvss epss 0.02

    Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

  • CVE-1999-1075Mar 18, 1998
    risk 0.00cvss epss 0.01

    inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1,…

  • CVE-1999-1486Feb 25, 1998
    risk 0.00cvss epss 0.00

    sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-1999-0087Feb 1, 1998
    risk 0.00cvss epss 0.01

    Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.

  • CVE-1999-1487Jan 21, 1998
    risk 0.00cvss epss 0.00

    Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.

  • CVE-1999-0086Jan 8, 1998
    risk 0.00cvss epss 0.02

    AIX routed allows remote users to modify sensitive files.

  • CVE-1999-0017Dec 10, 1997
    risk 0.00cvss epss 0.02

    FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

  • CVE-1999-0097Oct 29, 1997
    risk 0.00cvss epss 0.04

    The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

  • CVE-1999-0093Oct 29, 1997
    risk 0.00cvss epss 0.00

    AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.

  • CVE-1999-0094Oct 29, 1997
    risk 0.00cvss epss 0.00

    AIX piodmgrsu command allows local users to gain additional group privileges.

  • CVE-1999-0091Oct 28, 1997
    risk 0.00cvss epss 0.00

    Buffer overflow in AIX writesrv command allows local users to obtain root access.

Page 176 of 177