Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aix HIGH 7.2
CVE-2008-1596

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1599

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoki…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1600

The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a diffe…

Patch available
Fix from $1,950 2008-03-31
Websphere Application Server HIGH 10.0
CVE-2008-0741

Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has un…

Fix: after 6.0.2.24
Fix from $1,950 2008-02-13
Db2 Universal Database MEDIUM 6.9
CVE-2007-5757

Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gai…

Fix: after 8.0
Fix from $1,600 2008-02-13
Db2 HIGH 7.5
CVE-2008-0696

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.2
CVE-2008-0697

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-12
Aix HIGH 7.2
CVE-2008-0584

Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) s…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0588

Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2008-02-05
Aix MEDIUM 6.6
CVE-2008-0585

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "…

Mitigation only
Fix from $1,600 2008-02-05
Websphere Business Modeler MEDIUM 6.0
CVE-2008-0402

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to byp…

Patch available
Fix from $1,600 2008-01-23
Lotus Notes MEDIUM 6.9
CVE-2007-6594

IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0…

Fix: after 8.0.1
Fix from $1,600 2007-12-28
Db2 Universal Database HIGH 10.0
CVE-2007-6047

Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance o…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6048

IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor d…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6051

IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 7.2
CVE-2007-6049

Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to …

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 7.2
CVE-2007-6050

Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure di…

Fix: after 9.1
Fix from $1,950 2007-11-20
Rational Clearquest HIGH 7.5
CVE-2007-5090

Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt da…

No fix yet
Fix from $1,950 2007-09-26
Aix MEDIUM 6.6
CVE-2007-4798

Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have n…

Patch available
Fix from $1,600 2007-09-10
Websphere Application Server HIGH 7.5
CVE-2006-4136

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…

Fix: after 6.1.0.0
Fix from $1,950 2006-08-14
Tivoli Directory Server MEDIUM 5.8
CVE-2005-3567

slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and mod…

Patch available
Fix from $1,600 2005-11-16