Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3758EPSS 7%

Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3759

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a cert…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3761

Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 7.8
CVE-2010-3760

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not prop…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback MEDIUM 5.0
CVE-2010-3755

The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0…

Mitigation only
Fix from $1,600 2010-10-05
Tivoli Storage Manager Fastback MEDIUM 5.0
CVE-2010-3756

The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,600 2010-10-05
Db2 HIGH 7.2
CVE-2010-3733

The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow loca…

Mitigation only
Fix from $1,950 2010-10-05
Db2 Universal Database MEDIUM 6.4
CVE-2010-3739

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and…

Fix: after 9.5
Fix from $1,600 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3734

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easi…

Mitigation only
Fix from $1,600 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3738

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, in…

Mitigation only
Fix from $1,600 2010-10-05
Db2 HIGH 10.0
CVE-2010-3731EPSS 10%

Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration …

Mitigation only
Fix from $1,950 2010-10-05
Filenet P8 Application Engine MEDIUM 5.8
CVE-2010-3473

Open redirect vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allows remote atta…

Mitigation only
Fix from $1,600 2010-09-20
Db2 MEDIUM 5.0
CVE-2010-3474

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners…

Mitigation only
Fix from $1,600 2010-09-20
Filenet P8 Application Engine MEDIUM 6.4
CVE-2009-5002

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Au…

Mitigation only
Fix from $1,600 2010-09-20
Lotus Domino HIGH 9.3
CVE-2010-3407EPSS 41%

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x befo…

No fix yet
Fix from $1,950 2010-09-16
Aix MEDIUM 6.8
CVE-2010-3405

Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage …

Patch available
Fix from $1,600 2010-09-16
Lotus Sametime HIGH 10.0
CVE-2010-3398

Unspecified vulnerability in the webcontainer implementation in IBM Lotus Sametime Connect 8.5.1 before CF1 has unknown impact and attack vectors, ak…

Fix: after 8.5.1
Fix from $1,950 2010-09-15
Proventia Network Mail Security System Virtual Appliance MEDIUM 6.8
CVE-2010-0153

Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System …

Mitigation only
Fix from $1,600 2010-09-14
Filenet Content Manager MEDIUM 6.8
CVE-2010-3320

Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sit…

Mitigation only
Fix from $1,600 2010-09-13
Filenet Content Manager MEDIUM 5.0
CVE-2010-3318

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive informati…

Mitigation only
Fix from $1,600 2010-09-13
Filenet Content Manager MEDIUM 5.0
CVE-2010-3319

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive inf…

Mitigation only
Fix from $1,600 2010-09-13
Db2 HIGH 10.0
CVE-2010-3193

Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2010-08-31
Db2 HIGH 7.5
CVE-2010-3194

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via un…

Mitigation only
Fix from $1,950 2010-08-31
Db2 MEDIUM 5.0
CVE-2010-3195

Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of …

Mitigation only
Fix from $1,600 2010-08-31
Db2 MEDIUM 5.0
CVE-2010-3197

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote …

Mitigation only
Fix from $1,600 2010-08-31
Aix HIGH 10.0
CVE-2010-3187EPSS 20%

Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

Fix: after 5.3
Fix from $1,950 2010-08-30
Websphere Application Server HIGH 10.0
CVE-2010-3186

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, …

Mitigation only
Fix from $1,950 2010-08-30
Tivoli Storage Manager Fastback HIGH 7.5
CVE-2010-3058

The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remot…

Mitigation only
Fix from $1,950 2010-08-20
Tivoli Storage Manager Fastback HIGH 7.5
CVE-2010-3059

Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, al…

Mitigation only
Fix from $1,950 2010-08-20
Tivoli Storage Manager Fastback MEDIUM 5.0
CVE-2010-3060

Unspecified vulnerability in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6…

Mitigation only
Fix from $1,600 2010-08-20