Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aix HIGH 7.2
CVE-2007-4796

Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2007-09-10
Aix HIGH 7.2
CVE-2007-4797

Multiple buffer overflows in unspecified svprint (System V print) commands in bos.svprint.rte in IBM AIX 5.2 and 5.3 allow local users to gain privil…

Patch available
Fix from $1,950 2007-09-10
Aix MEDIUM 6.6
CVE-2007-4798

Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have n…

Patch available
Fix from $1,600 2007-09-10
Db2 Universal Database MEDIUM 6.9
CVE-2007-4270

Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on …

Fix: after 9.1
Fix from $1,600 2007-08-18
Db2 Universal Database MEDIUM 6.9
CVE-2007-4275

Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via cer…

Fix: after 9.1
Fix from $1,600 2007-08-18
Db2 Universal Database MEDIUM 6.9
CVE-2007-4276

Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF a…

Fix: after 9.1
Fix from $1,600 2007-08-18
Db2 Universal Database MEDIUM 6.0
CVE-2007-4417

IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to exe…

Fix: after 9.1
Fix from $1,600 2007-08-18
Db2 Universal Database MEDIUM 5.5
CVE-2007-4418

IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have…

Fix: after 8.0
Fix from $1,600 2007-08-18
Db2 Universal Database MEDIUM 5.0
CVE-2007-4423

Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of serv…

Patch available
Fix from $1,600 2007-08-18
Rational Clearquest HIGH 7.5
CVE-2007-4368

SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL …

No fix yet
Fix from $1,950 2007-08-15
Aix HIGH 7.2
CVE-2007-4354

Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2007-08-15
Aix HIGH 7.2
CVE-2007-4355

Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2007-08-15
Aix MEDIUM 6.9
CVE-2007-4353

Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the …

Patch available
Fix from $1,600 2007-08-15
Aix MEDIUM 6.9
CVE-2007-4236

Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.

Patch available
Fix from $1,600 2007-08-08
Aix MEDIUM 6.9
CVE-2007-4237

Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.

Patch available
Fix from $1,600 2007-08-08
Aix MEDIUM 6.9
CVE-2007-4238

AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root pr…

Mitigation only
Fix from $1,600 2007-08-08
Aix MEDIUM 6.9
CVE-2007-3333

Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal …

Mitigation only
Fix from $1,600 2007-07-26
Aix MEDIUM 6.9
CVE-2007-4003

pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argu…

Mitigation only
Fix from $1,600 2007-07-26
Aix MEDIUM 6.9
CVE-2007-4004

Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the …

Mitigation only
Fix from $1,600 2007-07-26
Websphere Application Server HIGH 9.3
CVE-2007-3960

Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, …

Fix: after 6.0.2.19
Fix from $1,950 2007-07-24
Tivoli Provisioning Manager Os Deployment HIGH 7.5
CVE-2007-3268

The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,950 2007-07-18
Proventia Network Ips Gx5008 HIGH 9.3
CVE-2007-3831

PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code vi…

Mitigation only
Fix from $1,950 2007-07-17
Aix HIGH 7.2
CVE-2007-3680

Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a lo…

Patch available
Fix from $1,950 2007-07-11
Os 400 HIGH 7.8
CVE-2007-3537

IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain syst…

Mitigation only
Fix from $1,950 2007-07-03
Websphere Application Server MEDIUM 5.0
CVE-2007-3397

The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different r…

Patch available
Fix from $1,600 2007-06-26
Websphere Application Server HIGH 10.0
CVE-2007-3263

Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and att…

Fix: after 6.1.0.7
Fix from $1,950 2007-06-19
Websphere Application Server HIGH 10.0
CVE-2007-3264

Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vecto…

Fix: after 6.1.0.7
Fix from $1,950 2007-06-19
Websphere Application Server HIGH 7.8
CVE-2007-3262

Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to…

Fix: after 6.1.0.7
Fix from $1,950 2007-06-19
Websphere Portal MEDIUM 6.4
CVE-2007-3128

SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL comma…

Mitigation only
Fix from $1,600 2007-06-19
Websphere Portal MEDIUM 5.0
CVE-2007-3127

content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) …

Mitigation only
Fix from $1,600 2007-06-19