Vulnerability index

Browse CVEs

2,232 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Informix Web Datablade HIGH 7.5
CVE-2002-0554EPSS 7%

webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack …

No fix yet
Fix from $1,950 2002-07-03
Informix Web Datablade HIGH 7.5
CVE-2002-0555

IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in…

Mitigation only
Fix from $1,950 2002-07-03
Lotus Domino Server HIGH 7.5
CVE-2002-0037

Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes AP…

Mitigation only
Fix from $1,950 2002-04-22
Aix MEDIUM 5.0
CVE-2002-1619

Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).

Mitigation only
Fix from $1,600 2002-03-08
Lotus Notes HIGH 7.5
CVE-2001-1504

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automaticall…

Mitigation only
Fix from $1,950 2001-12-31
Aix HIGH 7.5
CVE-2001-1529

Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of detai…

Mitigation only
Fix from $1,950 2001-12-31
Aix HIGH 7.5
CVE-2001-1557

Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.

Mitigation only
Fix from $1,950 2001-12-31
Aix MEDIUM 5.0
CVE-2001-1554

IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (P…

Mitigation only
Fix from $1,600 2001-12-31
Aix HIGH 10.0
CVE-2001-1440EPSS 5%

Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.

Mitigation only
Fix from $1,950 2001-12-21
Tivoli Secureway Policy Director MEDIUM 5.0
CVE-2001-1191

WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.

Mitigation only
Fix from $1,600 2001-12-11
Lotus Domino MEDIUM 5.0
CVE-2000-1215

The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of…

Mitigation only
Fix from $1,600 2001-09-19
Aix HIGH 10.0
CVE-2001-1061

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

No fix yet
Fix from $1,950 2001-08-31
Aix HIGH 7.2
CVE-2001-0533

Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

Mitigation only
Fix from $1,950 2001-08-14
Alphaworks Tftp Server HIGH 7.5
CVE-2001-1265

Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary fil…

No fix yet
Fix from $1,950 2001-07-20
Secureway Directory HIGH 7.5
CVE-2001-1309EPSS 5%

Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstra…

Mitigation only
Fix from $1,950 2001-07-16
Db2 Universal Database MEDIUM 5.0
CVE-2001-1143

IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port…

Mitigation only
Fix from $1,600 2001-07-11
Visualage For Java MEDIUM 6.8
CVE-2001-1441

Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via th…

No fix yet
Fix from $1,600 2001-07-02
Net.commerce MEDIUM 5.0
CVE-2001-0389

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEX…

No fix yet
Fix from $1,600 2001-07-02
Net.commerce MEDIUM 5.0
CVE-2001-0390EPSS 5%

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %…

No fix yet
Fix from $1,600 2001-07-02
Aix Snmp MEDIUM 5.0
CVE-2001-0487

AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.

Mitigation only
Fix from $1,600 2001-06-27
Aix HIGH 10.0
CVE-2001-1080EPSS 6%

diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privile…

Mitigation only
Fix from $1,950 2001-06-19
Websphere Commerce Suite MEDIUM 5.0
CVE-2001-0446

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to…

Mitigation only
Fix from $1,600 2001-06-18
Aix HIGH 7.2
CVE-2001-1329

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

No fix yet
Fix from $1,950 2001-06-11
Aix HIGH 7.2
CVE-2001-1330

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

No fix yet
Fix from $1,950 2001-06-11
Net.commerce HIGH 7.5
CVE-2001-0319EPSS 7%

orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of th…

No fix yet
Fix from $1,950 2001-05-03
Lotus Domino Server MEDIUM 5.0
CVE-1999-0729

Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.

No fix yet
Fix from $1,600 2001-03-12
Db2 Universal Database HIGH 7.5
CVE-2001-0051

IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the …

No fix yet
Fix from $1,950 2001-02-16
HTTP Server HIGH 7.5
CVE-2000-1168

IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET r…

Mitigation only
Fix from $1,950 2001-01-09
Net.data MEDIUM 5.0
CVE-2000-1110

document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a non…

No fix yet
Fix from $1,600 2001-01-09
Lotus Notes MEDIUM 5.0
CVE-2000-1117

The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine t…

No fix yet
Fix from $1,600 2001-01-09