Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server HIGH 10.0
CVE-2008-2221

Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack…

Mitigation only
Fix from $1,950 2008-05-14
Rational Build Forge HIGH 7.5
CVE-2008-2122

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent …

Mitigation only
Fix from $1,950 2008-05-09
Db2 HIGH 9.0
CVE-2008-1997

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated user…

Mitigation only
Fix from $1,950 2008-04-28
Db2 HIGH 8.5
CVE-2008-1998

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users …

Mitigation only
Fix from $1,950 2008-04-28
Lotus Expeditor Client HIGH 9.3
CVE-2008-1965EPSS 11%

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus S…

No fix yet
Fix from $1,950 2008-04-25
Db2 Universal Database MEDIUM 6.9
CVE-2007-5664

db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 …

Patch available
Fix from $1,600 2008-04-16
Db2 Universal Database MEDIUM 6.9
CVE-2007-5758

Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix P…

No fix yet
Fix from $1,600 2008-04-16
Lotus Notes HIGH 9.3
CVE-2007-5406

kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Secur…

Fix: after 7.5
Fix from $1,950 2008-04-10
Aix HIGH 7.2
CVE-2008-1710

Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.

Mitigation only
Fix from $1,950 2008-04-09
Soliddb MEDIUM 6.8
CVE-2008-1705

Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via forma…

No fix yet
Fix from $1,600 2008-04-09
Db2 Content Manager HIGH 10.0
CVE-2008-1681

Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privileg…

Fix: after 8.3
Fix from $1,950 2008-04-04
Aix HIGH 7.2
CVE-2008-1593

The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to re…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1596

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1599

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoki…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1600

The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a diffe…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1601

Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.

Mitigation only
Fix from $1,950 2008-03-31
Informix Dynamic Server HIGH 10.0
CVE-2008-0949

Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection…

Mitigation only
Fix from $1,950 2008-03-18
Informix Dynamic Server HIGH 8.5
CVE-2008-0727EPSS 5%

Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2008-03-18
Rational Clearquest MEDIUM 5.0
CVE-2008-1287

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows re…

Patch available
Fix from $1,600 2008-03-11
Rational Clearquest MEDIUM 5.0
CVE-2008-1288

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

Patch available
Fix from $1,600 2008-03-11
Aix MEDIUM 6.9
CVE-2008-1274

Untrusted search path vulnerability in man in IBM AIX 6.1.0 allows local users to execute arbitrary code via a malicious program in the man directory.

Mitigation only
Fix from $1,600 2008-03-10
Lotus Notes HIGH 9.3
CVE-2007-6706

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attack…

Fix: after 7.0.2
Fix from $1,950 2008-03-09
Lotus Notes HIGH 9.3
CVE-2008-1217

Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers…

Mitigation only
Fix from $1,950 2008-03-09
Lotus Quickr Server MEDIUM 6.8
CVE-2008-1216

IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which…

Mitigation only
Fix from $1,600 2008-03-09
Websphere Mq MEDIUM 6.6
CVE-2008-1130

Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a qu…

Mitigation only
Fix from $1,600 2008-03-04
Informix Dynamic Server HIGH 10.0
CVE-2008-0768

Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynami…

Fix: after 11.10.xc2
Fix from $1,950 2008-02-13
Websphere Application Server HIGH 10.0
CVE-2008-0741

Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has un…

Fix: after 6.0.2.24
Fix from $1,950 2008-02-13
Db2 HIGH 10.0
CVE-2007-3676

IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial o…

Fix: after 9.0
Fix from $1,950 2008-02-13
Db2 Universal Database MEDIUM 6.9
CVE-2007-5757

Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gai…

Fix: after 8.0
Fix from $1,600 2008-02-13
Db2 HIGH 9.0
CVE-2008-0699EPSS 5%

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 a…

Patch available
Fix from $1,950 2008-02-12