Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Domino Web Access HIGH 7.6
CVE-2010-0919EPSS 6%

Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, …

Fix: after 229.271
Fix from $1,950 2010-03-03
Lotus Inotes MEDIUM 6.8
CVE-2010-0921

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote …

Fix: after 229.271
Fix from $1,600 2010-03-03
Websphere Portal MEDIUM 6.8
CVE-2010-0715

Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Managem…

Patch available
Fix from $1,600 2010-02-26
Websphere Application Server MEDIUM 5.0
CVE-2010-0563

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configur…

Patch available
Fix from $1,600 2010-02-08
Cognos Express HIGH 7.5
CVE-2010-0557EPSS 51%

IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging ha…

Mitigation only
Fix from $1,950 2010-02-05
Websphere Service Registry And Repository MEDIUM 5.5
CVE-2009-2750

IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration properties, which allows remote authen…

Patch available
Fix from $1,600 2010-02-04
Db2 MEDIUM 5.0
CVE-2010-0472

kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) …

No fix yet
Fix from $1,600 2010-02-02
Db2 MEDIUM 6.5
CVE-2010-0462EPSS 8%

Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified imp…

No fix yet
Fix from $1,600 2010-01-28
Lotus Domino HIGH 10.0
CVE-2010-0358

Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and pos…

Mitigation only
Fix from $1,950 2010-01-20
Tivoli Directory Server MEDIUM 5.0
CVE-2010-0312

The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL p…

No fix yet
Fix from $1,600 2010-01-14
Lotus Inotes HIGH 10.0
CVE-2009-4594

Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, a…

Fix: after 229.111
Fix from $1,950 2010-01-09
Lotus Inotes HIGH 10.0
CVE-2010-0274

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino …

Fix: after 229.231
Fix from $1,950 2010-01-09
Lotus Inotes HIGH 10.0
CVE-2010-0275

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in t…

Fix: after 229.231
Fix from $1,950 2010-01-09
Domino Web Access HIGH 10.0
CVE-2010-0276

IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyw…

No fix yet
Fix from $1,950 2010-01-09
Db2 MEDIUM 6.5
CVE-2009-4438

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege require…

Patch available
Fix from $1,600 2009-12-28
Aix HIGH 7.2
CVE-2009-4361

Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges vi…

Mitigation only
Fix from $1,950 2009-12-21
Aix HIGH 7.2
CVE-2009-4362

Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via…

Mitigation only
Fix from $1,950 2009-12-21
Rational Clearcase MEDIUM 5.0
CVE-2009-4357

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might al…

Fix: after 7.1
Fix from $1,600 2009-12-18
Db2 HIGH 10.0
CVE-2009-4335

Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and…

Patch available
Fix from $1,950 2009-12-16
Db2 HIGH 7.5
CVE-2009-4333

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st…

Patch available
Fix from $1,950 2009-12-16
Db2 HIGH 7.2
CVE-2009-4330

Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.

Patch available
Fix from $1,950 2009-12-16
Db2 HIGH 7.2
CVE-2009-4331

The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and a…

Patch available
Fix from $1,950 2009-12-16
Db2 MEDIUM 6.4
CVE-2009-4325

The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified point…

Patch available
Fix from $1,600 2009-12-16
Db2 MEDIUM 5.0
CVE-2009-4327

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a c…

Patch available
Fix from $1,600 2009-12-16
Db2 MEDIUM 5.0
CVE-2009-4332

db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer…

Patch available
Fix from $1,600 2009-12-16
Infosphere Information Server HIGH 10.0
CVE-2009-4240

Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unkno…

No fix yet
Fix from $1,950 2009-12-09
Websphere Application Server MEDIUM 6.4
CVE-2009-2749

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session value…

Fix: after 1.0
Fix from $1,600 2009-12-08
Websphere Portal HIGH 7.5
CVE-2009-4153

Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to t…

Patch available
Fix from $1,950 2009-12-02
Websphere Application Server MEDIUM 6.8
CVE-2009-2746

Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0…

Patch available
Fix from $1,600 2009-11-16
Advanced Management Module Firmware HIGH 10.0
CVE-2009-3935

Multiple unspecified vulnerabilities in the Advanced Management Module firmware before 2.50G for the IBM BladeCenter T 8720-2xx and 8730-2xx have unk…

Fix: after 2.50c
Fix from $1,950 2009-11-12