VYPR

Vendor CVEs

IBM

All CVEs

8,825 total · sorted by risk
  • CVE-2017-1093HigFeb 2, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.

  • CVE-2016-9739HigFeb 1, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.

  • CVE-2016-6065HigFeb 1, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.

  • CVE-2016-5985HigFeb 1, 2017
    risk 0.51cvss 7.8epss 0.00

    The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local attacker could overflow a buffer and execute arbitrary code on the system or cause a system crash.

  • CVE-2016-2946HigDec 1, 2016
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.

  • CVE-2016-2871HigNov 30, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.

  • CVE-2016-2948HigNov 30, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

  • CVE-2016-0328HigOct 22, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.

  • CVE-2016-0247HigOct 22, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.

  • CVE-2016-0287HigJul 8, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.

  • CVE-2016-0301HigJun 26, 2016
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0279.

  • CVE-2016-0279HigJun 26, 2016
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0301.

  • CVE-2016-0278HigJun 26, 2016
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0279, and CVE-2016-0301.

  • CVE-2016-0277HigJun 26, 2016
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0278, CVE-2016-0279, and CVE-2016-0301.

  • CVE-2016-0226HigMar 28, 2016
    risk 0.51cvss 7.8epss 0.00

    The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.

  • CVE-2015-7489HigJan 1, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.

  • CVE-2007-5544HigOct 29, 2007
    risk 0.51cvss 7.8epss 0.00

    IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus…

  • CVE-2003-0578HigAug 18, 2003
    risk 0.51cvss 7.8epss 0.00

    cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.

  • CVE-1999-0022HigJul 3, 1996
    risk 0.51cvss 7.8epss 0.01

    Local user gains root privileges via buffer overflow in rdist, via expstr() function.

  • CVE-2026-17423HigAug 20, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.

  • CVE-2026-17024HigAug 20, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.

  • CVE-2026-17003HigAug 20, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.

  • CVE-2026-16819HigAug 19, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.

  • CVE-2026-14866HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

  • CVE-2026-16863HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

  • CVE-2026-8183HigAug 5, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request…

  • CVE-2026-8856HigMay 26, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

  • CVE-2026-3357HigApr 8, 2026
    risk 0.50cvss 8.8epss 0.00

    IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

  • CVE-2025-64645HigDec 26, 2025
    risk 0.50cvss 7.7epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

  • CVE-2024-38329HigJun 19, 2024
    risk 0.50cvss 7.7epss 0.00

    IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker…

  • CVE-2024-35140HigMay 31, 2024
    risk 0.50cvss 7.7epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.

  • CVE-2020-4509HigJun 4, 2020
    risk 0.50cvss 7.6epss 0.02

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364.

  • CVE-2018-1618HigApr 2, 2019
    risk 0.50cvss 7.7epss 0.03

    IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force…

  • CVE-2018-1778HigDec 20, 2018
    risk 0.50cvss 7.7epss 0.03

    IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can…

  • CVE-2018-1821HigDec 13, 2018
    risk 0.50cvss 7.1epss 0.16

    IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2018-1744HigOct 15, 2018
    risk 0.50cvss 7.7epss 0.03

    IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID:…

  • CVE-2018-1649HigOct 5, 2018
    risk 0.50cvss 7.7epss 0.03

    IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.

  • CVE-2018-1448HigMar 22, 2018
    risk 0.50cvss 7.7epss 0.00

    IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.

  • CVE-2016-0362HigJul 1, 2016
    risk 0.50cvss 7.7epss 0.01

    IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy…

  • CVE-2016-0267HigJun 29, 2016
    risk 0.50cvss 7.7epss 0.01

    IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.

  • CVE-2015-7400HigJan 2, 2016
    risk 0.50cvss 7.7epss 0.03

    The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

  • CVE-2026-19446HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.

  • CVE-2026-17425HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.

  • CVE-2026-17170HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.

  • CVE-2026-17165HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

  • CVE-2026-17163HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field.

  • CVE-2026-17159HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.

  • CVE-2026-17121HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

  • CVE-2026-16928HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.

  • CVE-2026-16924HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.

Page 23 of 177