Vulnerability index

Browse CVEs

201 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2008-1596 Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to… Aix Patch available Fix from $1,9502008-03-31 HIGH 7.2 CVE-2008-1599 The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoki… Aix Patch available Fix from $1,9502008-03-31 HIGH 7.2 CVE-2008-1600 The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a diffe… Aix Patch available Fix from $1,9502008-03-31 HIGH 10.0 CVE-2008-0741 Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has un… Websphere Application Server after 6.0.2.24 Fix from $1,9502008-02-13 MEDIUM 6.9 CVE-2007-5757 Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gai… Db2 Universal Database after 8.0 Fix from $1,6002008-02-13 HIGH 7.5 CVE-2008-0696 IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors. Db2 Mitigation only Fix from $1,9502008-02-12 HIGH 7.2 CVE-2008-0697 Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors. Db2 Mitigation only Fix from $1,9502008-02-12 HIGH 7.2 CVE-2008-0584 Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) s… Aix Mitigation only Fix from $1,9502008-02-05 HIGH 7.2 CVE-2008-0588 Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors. Aix Patch available Fix from $1,9502008-02-05 MEDIUM 6.6 CVE-2008-0585 sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "… Aix Mitigation only Fix from $1,6002008-02-05 MEDIUM 6.0 CVE-2008-0402 Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to byp… Websphere Business Modeler Patch available Fix from $1,6002008-01-23 MEDIUM 6.9 CVE-2007-6594 IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0… Lotus Notes after 8.0.1 Fix from $1,6002007-12-28 HIGH 10.0 CVE-2007-6047 Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance o… Db2 Universal Database after 9.1 Fix from $1,9502007-11-20 HIGH 10.0 CVE-2007-6048 IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor d… Db2 Universal Database after 9.1 Fix from $1,9502007-11-20 HIGH 10.0 CVE-2007-6051 IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE… Db2 Universal Database after 9.1 Fix from $1,9502007-11-20 HIGH 7.2 CVE-2007-6049 Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to … Db2 Universal Database after 9.1 Fix from $1,9502007-11-20 HIGH 7.2 CVE-2007-6050 Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure di… Db2 Universal Database after 9.1 Fix from $1,9502007-11-20 HIGH 7.5 CVE-2007-5090 Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt da… Rational Clearquest No fix yet Fix from $1,9502007-09-26 MEDIUM 6.6 CVE-2007-4798 Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have n… Aix Patch available Fix from $1,6002007-09-10 HIGH 7.5 CVE-2006-4136 Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA… Websphere Application Server after 6.1.0.0 Fix from $1,9502006-08-14 MEDIUM 5.8 CVE-2005-3567 slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and mod… Tivoli Directory Server Patch available Fix from $1,6002005-11-16