Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 MEDIUM 5.0
CVE-2008-4693

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attacker…

Fix: after 9.5
Fix from $1,600 2008-10-22
Websphere Application Server HIGH 7.8
CVE-2008-4678

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attacker…

Mitigation only
Fix from $1,950 2008-10-22
Websphere Application Server MEDIUM 6.8
CVE-2008-4679

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store C…

Patch available
Fix from $1,600 2008-10-22
Lotus Quickr HIGH 7.5
CVE-2008-4507

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author …

Mitigation only
Fix from $1,950 2008-10-09
Lotus Quickr HIGH 7.8
CVE-2008-4505

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a…

Mitigation only
Fix from $1,950 2008-10-09
Lotus Quickr HIGH 7.5
CVE-2008-4506

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" vi…

Mitigation only
Fix from $1,950 2008-10-09
Zseries HIGH 10.0
CVE-2008-4404

The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which a…

Mitigation only
Fix from $1,950 2008-10-03
Tivoli Netcool Webtop HIGH 7.2
CVE-2008-4294

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a s…

Patch available
Fix from $1,950 2008-09-27
Websphere Application Server HIGH 9.3
CVE-2008-4111

Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, wh…

Patch available
Fix from $1,950 2008-09-16
Aix HIGH 7.2
CVE-2008-4018

swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establi…

Mitigation only
Fix from $1,950 2008-09-11
Db2 HIGH 7.5
CVE-2008-3958

IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that si…

Fix: after 8.0
Fix from $1,950 2008-09-11
Db2 MEDIUM 5.0
CVE-2008-3959

IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash)…

Fix: after 8.2
Fix from $1,600 2008-09-11
Db2 Universal Database MEDIUM 5.0
CVE-2008-3960

Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial …

Fix: after 8.2
Fix from $1,600 2008-09-11
Aix HIGH 7.2
CVE-2007-6717

Buffer overflow in tftp in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2008-09-11
Db2 Universal Database HIGH 9.3
CVE-2008-3853EPSS 6%

Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to…

Patch available
Fix from $1,950 2008-08-28
Db2 Universal Database HIGH 7.8
CVE-2008-3854

Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (sys…

Patch available
Fix from $1,950 2008-08-28
Db2 Universal Database HIGH 7.5
CVE-2008-3856

The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of …

Fix: after 9.1
Fix from $1,950 2008-08-28
Db2 Universal Database MEDIUM 6.5
CVE-2008-3852

Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IB…

Fix: after 9.5
Fix from $1,600 2008-08-28
Rational Clearquest MEDIUM 5.0
CVE-2008-3550

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co…

Mitigation only
Fix from $1,600 2008-08-08
Websphere Portal HIGH 7.5
CVE-2008-3423

IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

Patch available
Fix from $1,950 2008-08-04
Websphere Application Server HIGH 10.0
CVE-2008-3235

Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1…

No fix yet
Fix from $1,950 2008-07-21
Websphere Application Server MEDIUM 5.0
CVE-2008-3236

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo…

Mitigation only
Fix from $1,600 2008-07-21
Data Ontap HIGH 10.0
CVE-2008-3160

Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer and IBM System Storage N series…

Fix: after 7.1
Fix from $1,950 2008-07-14
Tivoli Directory Server MEDIUM 6.0
CVE-2008-2943

Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial …

Mitigation only
Fix from $1,600 2008-06-30
Afp Viewer Plug In HIGH 9.3
CVE-2008-2880

Heap-based buffer overflow in the IBM AFP Viewer Plug-in 2.0.7.1 and 3.2.1.1 allows remote attackers to execute arbitrary code via a long SRC propert…

Patch available
Fix from $1,950 2008-06-26
Websphere Application Server MEDIUM 5.0
CVE-2008-2550

Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and…

Fix: after 6.1.0.16
Fix from $1,600 2008-06-04
Aix HIGH 7.2
CVE-2008-2513

Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.

Patch available
Fix from $1,950 2008-06-02
Aix HIGH 7.2
CVE-2008-2515

Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment…

Patch available
Fix from $1,950 2008-06-02
Lotus Sametime HIGH 7.5
CVE-2008-2499EPSS 77%

Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before …

Fix: 8.0.1+
Fix from $1,950 2008-05-29
Lotus Domino HIGH 10.0
CVE-2008-2240EPSS 65%

Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a …

Patch available
Fix from $1,950 2008-05-22