Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Totalstorage Ds400 HIGH 10.0
CVE-2007-3232

The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator acco…

Mitigation only
Fix from $1,950 2007-06-15
Lotus Domino HIGH 9.3
CVE-2007-0068

IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote au…

Mitigation only
Fix from $1,950 2007-06-06
Lotus Domino Web Server HIGH 7.8
CVE-2007-0067EPSS 14%

Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of…

Patch available
Fix from $1,950 2007-06-06
Aix MEDIUM 6.6
CVE-2007-2996

Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain …

Patch available
Fix from $1,600 2007-06-04
Db2 HIGH 10.0
CVE-2007-2582EPSS 27%

Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary c…

Fix: after 9.0
Fix from $1,950 2007-05-10
Websphere Application Server HIGH 10.0
CVE-2006-7198

Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and att…

Fix: after 6.0.2.11
Fix from $1,950 2007-04-30
Tivoli Monitoring Express HIGH 10.0
CVE-2007-2137EPSS 8%

Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitor…

Patch available
Fix from $1,950 2007-04-22
Websphere Application Server HIGH 7.5
CVE-2007-1945

Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack …

Fix: after 6.1.0.1
Fix from $1,950 2007-04-11
Websphere Application Server MEDIUM 5.0
CVE-2007-1944

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vec…

Fix: after 6.1.0.1
Fix from $1,600 2007-04-11
Tivoli Provisioning Manager Os Deployment HIGH 10.0
CVE-2007-1868EPSS 59%

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTT…

Patch available
Fix from $1,950 2007-04-04
Aix HIGH 7.2
CVE-2007-1798

Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary co…

Mitigation only
Fix from $1,950 2007-04-02
Lotus Sametime HIGH 9.3
CVE-2007-1784

The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL librari…

Fix: after 7.0
Fix from $1,950 2007-03-31
Lotus Domino HIGH 7.8
CVE-2007-1739

Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of …

No fix yet
Fix from $1,950 2007-03-28
Lotus Domino HIGH 10.0
CVE-2007-1675EPSS 61%

Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 all…

Patch available
Fix from $1,950 2007-03-28
Websphere Application Server HIGH 7.5
CVE-2007-1608

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and c…

Fix: after 6.0.2.15
Fix from $1,950 2007-03-22
Websphere Application Server MEDIUM 5.0
CVE-2006-7166

IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a s…

Patch available
Fix from $1,600 2007-03-20
Db2 Universal Database HIGH 7.2
CVE-2007-1086

Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecif…

Patch available
Fix from $1,950 2007-02-23
Db2 HIGH 7.2
CVE-2007-1087

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arb…

Patch available
Fix from $1,950 2007-02-23
Db2 HIGH 7.2
CVE-2007-1088

Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long str…

Patch available
Fix from $1,950 2007-02-23
Db2 Universal Database HIGH 7.2
CVE-2007-1089

IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL…

Fix: after 9.1
Fix from $1,950 2007-02-23
Aix HIGH 7.2
CVE-2007-0978

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

Mitigation only
Fix from $1,950 2007-02-16
Lotus Domino HIGH 7.1
CVE-2007-0977EPSS 19%

IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible thr…

No fix yet
Fix from $1,950 2007-02-16
Aix HIGH 7.5
CVE-2007-0618

Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving a…

Patch available
Fix from $1,950 2007-01-31
Os 400 MEDIUM 5.0
CVE-2007-0442

Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-T…

Mitigation only
Fix from $1,600 2007-01-23
Os 400 HIGH 10.0
CVE-2006-6836

Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.

No fix yet
Fix from $1,950 2006-12-31
Aix MEDIUM 5.0
CVE-2006-6914

Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspec…

Patch available
Fix from $1,600 2006-12-31
Websphere Application Server HIGH 10.0
CVE-2006-6636

Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impac…

Patch available
Fix from $1,950 2006-12-19
Websphere Application Server MEDIUM 5.0
CVE-2006-6637

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true …

Patch available
Fix from $1,600 2006-12-19
Db2 Universal Database MEDIUM 5.0
CVE-2006-6638

IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereferenc…

Patch available
Fix from $1,600 2006-12-19
Websphere Host On Demand HIGH 7.5
CVE-2006-6537

IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, rela…

Mitigation only
Fix from $1,950 2006-12-14