Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Lotus Domino Web Access HIGH 7.5
CVE-2006-4763

IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows…

Mitigation only
Fix from $1,950 2006-09-13
Aix HIGH 7.2
CVE-2006-4522

Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

No fix yet
Fix from $1,950 2006-09-01
Aix HIGH 7.2
CVE-2006-4416

Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point t…

Mitigation only
Fix from $1,950 2006-08-28
Informix Dynamic Database Server HIGH 7.5
CVE-2006-3854

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers t…

No fix yet
Fix from $1,950 2006-08-17
Informix Dynamic Database Server HIGH 7.5
CVE-2006-3860

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands v…

Mitigation only
Fix from $1,950 2006-08-17
Lotus Notes MEDIUM 5.0
CVE-2006-3778

IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option i…

No fix yet
Fix from $1,600 2006-07-24
Websphere Application Server MEDIUM 5.0
CVE-2006-1619

IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request wit…

Mitigation only
Fix from $1,600 2006-04-05
Websphere Application Server MEDIUM 6.4
CVE-2006-1093

Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,600 2006-03-09
Tivoli Directory Server MEDIUM 5.0
CVE-2006-0717EPSS 10%

IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532…

No fix yet
Fix from $1,600 2006-02-15
Lotus Domino Server MEDIUM 5.0
CVE-2006-0580

IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).

Mitigation only
Fix from $1,600 2006-02-08
Informix Dynamic Database Server HIGH 7.5
CVE-2005-3642

IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log…

Mitigation only
Fix from $1,950 2005-11-16
Db2 Universal Database HIGH 7.5
CVE-2005-3643

IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the gu…

Mitigation only
Fix from $1,950 2005-11-16
Db2 Content Manager MEDIUM 5.0
CVE-2005-3569

INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown a…

Mitigation only
Fix from $1,600 2005-11-16
Rational Clearquest MEDIUM 6.8
CVE-2005-2994

Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allo…

Mitigation only
Fix from $1,600 2005-09-20
Lotus Notes MEDIUM 5.0
CVE-2005-2696

IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensiti…

No fix yet
Fix from $1,600 2005-08-26
Lotus Domino MEDIUM 5.0
CVE-2005-2428EPSS 73%

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows…

No fix yet
Fix from $1,600 2005-08-03
Aix HIGH 7.2
CVE-2005-2236

Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via…

No fix yet
Fix from $1,950 2005-07-12
Lotus Notes MEDIUM 5.0
CVE-2005-2175EPSS 5%

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it ea…

Mitigation only
Fix from $1,600 2005-07-09
Iseries As 400 HIGH 7.5
CVE-2005-1238

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write ar…

Mitigation only
Fix from $1,950 2005-05-02
Aix HIGH 7.2
CVE-2005-0240

Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argum…

Mitigation only
Fix from $1,950 2005-05-02
Lotus Domino Server MEDIUM 5.0
CVE-2005-0986EPSS 7%

NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2005-05-02
Iseries As 400 MEDIUM 5.0
CVE-2005-1025

The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and t…

No fix yet
Fix from $1,600 2005-05-02
Websphere Application Server MEDIUM 5.0
CVE-2005-1112EPSS 9%

IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code…

Mitigation only
Fix from $1,600 2005-05-02
Iseries As 400 MEDIUM 5.0
CVE-2005-1133

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid …

Mitigation only
Fix from $1,600 2005-05-02
Os 400 MEDIUM 5.0
CVE-2005-1182

Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attack…

Mitigation only
Fix from $1,600 2005-05-02
Aix HIGH 7.2
CVE-2004-1028

Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the …

Mitigation only
Fix from $1,950 2005-01-10
Aix HIGH 7.2
CVE-2004-1054

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH env…

Mitigation only
Fix from $1,950 2005-01-10
Aix MEDIUM 6.9
CVE-2004-2697

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a comman…

No fix yet
Fix from $1,600 2004-12-31
Lotus Domino MEDIUM 6.4
CVE-2004-2369

Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in t…

No fix yet
Fix from $1,600 2004-12-31
Cloudscape HIGH 10.0
CVE-2004-0253

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, poss…

Mitigation only
Fix from $1,950 2004-11-23