Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Zseries HIGH 10.0
CVE-2008-4404

The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which a…

Mitigation only
Fix from $1,950 2008-10-03
Aix HIGH 7.2
CVE-2008-4018

swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establi…

Mitigation only
Fix from $1,950 2008-09-11
Rational Clearquest MEDIUM 5.0
CVE-2008-3550

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co…

Mitigation only
Fix from $1,600 2008-08-08
Websphere Application Server HIGH 10.0
CVE-2008-3235

Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1…

No fix yet
Fix from $1,950 2008-07-21
Websphere Application Server MEDIUM 5.0
CVE-2008-3236

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo…

Mitigation only
Fix from $1,600 2008-07-21
Tivoli Directory Server MEDIUM 6.0
CVE-2008-2943

Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial …

Mitigation only
Fix from $1,600 2008-06-30
Websphere Application Server HIGH 10.0
CVE-2008-2221

Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack…

Mitigation only
Fix from $1,950 2008-05-14
Rational Build Forge HIGH 7.5
CVE-2008-2122

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent …

Mitigation only
Fix from $1,950 2008-05-09
Db2 HIGH 9.0
CVE-2008-1997

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated user…

Mitigation only
Fix from $1,950 2008-04-28
Db2 HIGH 8.5
CVE-2008-1998

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users …

Mitigation only
Fix from $1,950 2008-04-28
Lotus Expeditor Client HIGH 9.3
CVE-2008-1965EPSS 11%

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus S…

No fix yet
Fix from $1,950 2008-04-25
Db2 Universal Database MEDIUM 6.9
CVE-2007-5758

Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix P…

No fix yet
Fix from $1,600 2008-04-16
Aix HIGH 7.2
CVE-2008-1710

Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.

Mitigation only
Fix from $1,950 2008-04-09
Soliddb MEDIUM 6.8
CVE-2008-1705

Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via forma…

No fix yet
Fix from $1,600 2008-04-09
Aix HIGH 7.2
CVE-2008-1601

Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.

Mitigation only
Fix from $1,950 2008-03-31
Informix Dynamic Server HIGH 10.0
CVE-2008-0949

Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection…

Mitigation only
Fix from $1,950 2008-03-18
Informix Dynamic Server HIGH 8.5
CVE-2008-0727EPSS 5%

Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2008-03-18
Aix MEDIUM 6.9
CVE-2008-1274

Untrusted search path vulnerability in man in IBM AIX 6.1.0 allows local users to execute arbitrary code via a malicious program in the man directory.

Mitigation only
Fix from $1,600 2008-03-10
Lotus Notes HIGH 9.3
CVE-2008-1217

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers…

Mitigation only
Fix from $1,950 2008-03-09
Lotus Quickr Server MEDIUM 6.8
CVE-2008-1216

IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which…

Mitigation only
Fix from $1,600 2008-03-09
Websphere Mq MEDIUM 6.6
CVE-2008-1130

Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a qu…

Mitigation only
Fix from $1,600 2008-03-04
Db2 HIGH 7.8
CVE-2008-0698

Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory ac…

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.5
CVE-2008-0696

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.2
CVE-2008-0697

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-12
Aix HIGH 7.2
CVE-2008-0584

Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) s…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0586

Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldele…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0587

Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-05
Aix MEDIUM 6.6
CVE-2008-0585

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "…

Mitigation only
Fix from $1,600 2008-02-05
Hardware Management Console HIGH 7.8
CVE-2008-0495

Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2008-01-30
Aix HIGH 7.2
CVE-2007-5764

Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line opti…

No fix yet
Fix from $1,950 2008-01-25