Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db2 HIGH 7.8
CVE-2008-0698

Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory ac…

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.5
CVE-2008-0696

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.2
CVE-2008-0697

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-12
Aix HIGH 7.2
CVE-2008-0584

Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) s…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0586

Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldele…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0587

Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0588

Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2008-02-05
Aix MEDIUM 6.6
CVE-2008-0585

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "…

Mitigation only
Fix from $1,600 2008-02-05
Hardware Management Console HIGH 7.8
CVE-2008-0495

Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2008-01-30
Aix HIGH 7.2
CVE-2007-5764

Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line opti…

No fix yet
Fix from $1,950 2008-01-25
Tivoli Provisioning Manager Os Deployment HIGH 10.0
CVE-2008-0401EPSS 8%

Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim…

Fix: after 5.1.0.2
Fix from $1,950 2008-01-23
Websphere Business Modeler MEDIUM 6.0
CVE-2008-0402

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to byp…

Patch available
Fix from $1,600 2008-01-23
Websphere Application Server HIGH 10.0
CVE-2008-0389

Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through …

Fix: after 5.1.1.17
Fix from $1,950 2008-01-23
Informix Dynamic Server HIGH 7.2
CVE-2008-0368

onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.

Mitigation only
Fix from $1,950 2008-01-19
Informix Dynamic Server MEDIUM 6.9
CVE-2008-0369

Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying th…

Mitigation only
Fix from $1,600 2008-01-19
Tivoli Storage Manager Express HIGH 10.0
CVE-2008-0247EPSS 8%

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows re…

Fix: after 5.3
Fix from $1,950 2008-01-12
Lotus Domino HIGH 7.8
CVE-2008-0243

Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

No fix yet
Fix from $1,950 2008-01-12
Websphere Application Server HIGH 10.0
CVE-2007-6679

Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vect…

Fix: after 6.0.2.24
Fix from $1,950 2008-01-10
Lotus Notes HIGH 8.8
CVE-2007-6593EPSS 6%

Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user…

Mitigation only
Fix from $1,950 2007-12-28
Lotus Notes MEDIUM 6.9
CVE-2007-6594

IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0…

Fix: after 8.0.1
Fix from $1,600 2007-12-28
Db2 Content Manager Toolkit HIGH 10.0
CVE-2007-6525

Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, re…

Mitigation only
Fix from $1,950 2007-12-27
Domino Web Access HIGH 9.3
CVE-2007-4474EPSS 44%

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa…

No fix yet
Fix from $1,950 2007-12-27
Tivoli Provisioning Manager Express MEDIUM 5.0
CVE-2007-6408

IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when c…

Mitigation only
Fix from $1,600 2007-12-17
Hardware Management Console HIGH 10.0
CVE-2007-6293

Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."

No fix yet
Fix from $1,950 2007-12-10
Director HIGH 7.8
CVE-2007-5612

CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and …

Fix: after 5.20.1
Fix from $1,950 2007-11-21
Websphere Mq HIGH 10.0
CVE-2007-6044

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of…

No fix yet
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6045

Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6047

Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance o…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6048

IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor d…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6051

IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE…

Fix: after 9.1
Fix from $1,950 2007-11-20