Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Powerha HIGH 7.8
CVE-2009-3900

Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remote attackers to modify the op…

Patch available
Fix from $1,950 2009-11-06
Tivoli Storage Manager HIGH 10.0
CVE-2009-3854EPSS 6%

Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows …

Patch available
Fix from $1,950 2009-11-04
Tivoli Storage Manager HIGH 9.3
CVE-2009-3853EPSS 37%

Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 b…

Patch available
Fix from $1,950 2009-11-04
Tivoli Storage Manager HIGH 9.3
CVE-2009-3855

Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manag…

Patch available
Fix from $1,950 2009-11-04
Runtimes For Java Technology HIGH 7.5
CVE-2009-3852

Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related t…

Fix: after 5.0.0
Fix from $1,950 2009-11-03
Vios HIGH 10.0
CVE-2009-3699EPSS 62%

Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earli…

Fix: after 2.1.0
Fix from $1,950 2009-10-15
Informix Client Sdk HIGH 9.3
CVE-2009-3691EPSS 7%

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attacke…

No fix yet
Fix from $1,950 2009-10-13
Aix HIGH 10.0
CVE-2009-3517

nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…

Patch available
Fix from $1,950 2009-10-01
Installation Manager HIGH 9.3
CVE-2009-3518EPSS 5%

Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot an…

Fix: after 1.3.2
Fix from $1,950 2009-10-01
Aix HIGH 7.2
CVE-2009-3516

gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to…

Patch available
Fix from $1,950 2009-10-01
Db2 HIGH 10.0
CVE-2009-3473

IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and re…

Mitigation only
Fix from $1,950 2009-09-29
Db2 HIGH 7.5
CVE-2009-3471

IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss …

Mitigation only
Fix from $1,950 2009-09-29
Db2 MEDIUM 6.5
CVE-2009-3472

IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, inser…

Mitigation only
Fix from $1,600 2009-09-29
Informix Dynamic Server MEDIUM 5.0
CVE-2009-3470

IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2009-09-29
Websphere Application Server HIGH 7.8
CVE-2009-2744

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unkn…

Patch available
Fix from $1,950 2009-09-21
Websphere Business Events HIGH 10.0
CVE-2009-2741

Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers t…

Mitigation only
Fix from $1,950 2009-09-18
Websphere Mq HIGH 8.8
CVE-2009-3160

IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows …

Patch available
Fix from $1,950 2009-09-10
Websphere Mq HIGH 7.8
CVE-2009-3159

Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2009-09-10
Websphere Mq HIGH 7.8
CVE-2009-3161

The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other …

Patch available
Fix from $1,950 2009-09-10
Lotus Notes HIGH 7.5
CVE-2009-3114

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2009-09-09
Websphere Application Server MEDIUM 5.0
CVE-2009-3106

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security const…

Patch available
Fix from $1,600 2009-09-08
Tivoli Directory Server HIGH 7.8
CVE-2009-3089

IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecifie…

No fix yet
Fix from $1,950 2009-09-08
Tivoli Directory Server HIGH 7.5
CVE-2009-3088

Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via u…

No fix yet
Fix from $1,950 2009-09-08
Lotus Domino MEDIUM 5.0
CVE-2009-3087

Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of se…

No fix yet
Fix from $1,600 2009-09-08
Tivoli Directory Server MEDIUM 5.0
CVE-2009-3090

Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors,…

No fix yet
Fix from $1,600 2009-09-08
Lotus Notes HIGH 9.3
CVE-2009-3037EPSS 6%

Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec M…

Patch available
Fix from $1,950 2009-09-01
Websphere Commerce Suite MEDIUM 5.0
CVE-2009-2956

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient acc…

Mitigation only
Fix from $1,600 2009-08-24
Db2 MEDIUM 5.0
CVE-2009-2858

Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption)…

Fix: after 8.1
Fix from $1,600 2009-08-19
Db2 MEDIUM 5.0
CVE-2009-2860

Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious pa…

Fix: after 8.1
Fix from $1,600 2009-08-19
Websphere Commerce HIGH 10.0
CVE-2008-6973

Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.

Patch available
Fix from $1,950 2009-08-13