Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lotus Notes Traveler MEDIUM 5.0
CVE-2010-4553

An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a de…

Fix: after 8.5.0.2
Fix from $1,600 2010-12-16
Lotus Notes Traveler MEDIUM 5.0
CVE-2010-4550

IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.

Fix: after 8.5.1.2
Fix from $1,600 2010-12-16
Lotus Notes Traveler MEDIUM 5.8
CVE-2009-5032

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes…

Fix: after 8.5.0.1
Fix from $1,600 2010-12-16
Websphere Commerce MEDIUM 5.0
CVE-2010-2639

IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving acc…

Mitigation only
Fix from $1,600 2010-12-06
Omnifind HIGH 9.3
CVE-2010-3894EPSS 12%

Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form i…

Fix: after 8.5
Fix from $1,950 2010-11-12
Omnifind HIGH 7.5
CVE-2010-3893

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP addre…

No fix yet
Fix from $1,950 2010-11-12
Omnifind HIGH 7.5
CVE-2010-3896

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers …

No fix yet
Fix from $1,950 2010-11-12
Omnifind HIGH 7.2
CVE-2010-3895

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first…

Fix: after 9.0
Fix from $1,950 2010-11-12
Omnifind MEDIUM 6.9
CVE-2010-4236

Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LI…

Fix: after 9.0
Fix from $1,600 2010-11-12
Omnifind MEDIUM 6.8
CVE-2010-3892

Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attacker…

Mitigation only
Fix from $1,600 2010-11-12
Omnifind MEDIUM 5.0
CVE-2010-3897

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which migh…

Mitigation only
Fix from $1,600 2010-11-12
Omnifind MEDIUM 5.0
CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remo…

Mitigation only
Fix from $1,600 2010-11-12
Omnifind MEDIUM 5.0
CVE-2010-3899

IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial …

No fix yet
Fix from $1,600 2010-11-12
Omnifind MEDIUM 6.8
CVE-2010-3891

Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 a…

Fix: after 9.0
Fix from $1,600 2010-11-12
Enovia HIGH 10.0
CVE-2010-4218

Unspecified vulnerability in Web Services in IBM ENOVIA 6 has unknown impact and attack vectors, related to a system that becomes "exposed to the int…

No fix yet
Fix from $1,950 2010-11-09
Tivoli Directory Server MEDIUM 5.0
CVE-2010-4216

IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, whi…

Mitigation only
Fix from $1,600 2010-11-09
Tivoli Directory Server MEDIUM 5.0
CVE-2010-4217

Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-T…

Mitigation only
Fix from $1,600 2010-11-09
Websphere Commerce MEDIUM 6.5
CVE-2010-2635

SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via uns…

Mitigation only
Fix from $1,600 2010-11-09
Websphere Application Server MEDIUM 6.0
CVE-2010-0785

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 b…

Mitigation only
Fix from $1,600 2010-11-09
Websphere Application Server MEDIUM 5.0
CVE-2010-0786

The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML We…

Mitigation only
Fix from $1,600 2010-11-09
Tivoli Provisioning Manager Os Deployment HIGH 7.5
CVE-2010-4121

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows…

Mitigation only
Fix from $1,950 2010-10-28
Rational Quality Manager MEDIUM 5.0
CVE-2010-4094EPSS 64%

The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier f…

Mitigation only
Fix from $1,600 2010-10-26
Informix Dynamic Server HIGH 10.0
CVE-2010-4070EPSS 5%

Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x be…

Mitigation only
Fix from $1,950 2010-10-25
Informix Dynamic Server HIGH 8.5
CVE-2010-4069

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3,…

Mitigation only
Fix from $1,950 2010-10-25
Soliddb MEDIUM 5.0
CVE-2010-4055EPSS 7%

Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumpt…

Fix: after 6.5.0.3
Fix from $1,600 2010-10-23
Soliddb MEDIUM 5.0
CVE-2010-4056EPSS 8%

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a…

Fix: after 6.5.0.3
Fix from $1,600 2010-10-23
Soliddb MEDIUM 5.0
CVE-2010-4057EPSS 7%

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing m…

Fix: after 6.5.0.3
Fix from $1,600 2010-10-23
Informix Dynamic Server HIGH 9.0
CVE-2010-4053

Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 …

Mitigation only
Fix from $1,950 2010-10-23
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3754

The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3757

Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 throug…

Mitigation only
Fix from $1,950 2010-10-05