Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tivoli Storage Manager HIGH 7.5
CVE-2006-6309

Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory l…

Fix: after 5.2.9
Fix from $1,950 2006-12-06
Tivoli Storage Manager HIGH 10.0
CVE-2006-5855EPSS 27%

Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service…

Patch available
Fix from $1,950 2006-12-06
Websphere Application Server HIGH 10.0
CVE-2006-6135

Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, re…

Patch available
Fix from $1,950 2006-11-28
Websphere Application Server HIGH 10.0
CVE-2006-6136

IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering…

Patch available
Fix from $1,950 2006-11-28
Lotus Notes MEDIUM 5.0
CVE-2006-5835EPSS 13%

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to pe…

Patch available
Fix from $1,600 2006-11-10
Lotus Domino HIGH 7.2
CVE-2006-5818

Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute …

Fix: after 7.0.1
Fix from $1,950 2006-11-08
Websphere Application Server HIGH 10.0
CVE-2006-5323

Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible securi…

Fix: after 6.1.0.1
Fix from $1,950 2006-10-17
Websphere Application Server HIGH 7.5
CVE-2006-5324

The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified acce…

Fix: after 6.1.0.1
Fix from $1,950 2006-10-17
Client Security Password Manager MEDIUM 6.4
CVE-2006-5161

IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtai…

Mitigation only
Fix from $1,600 2006-10-05
Aix HIGH 10.0
CVE-2006-5008

Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspec…

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5003

Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5005

Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors i…

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5006

Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5009

Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unsp…

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5010

Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a …

Patch available
Fix from $1,950 2006-09-27
Aix HIGH 7.2
CVE-2006-5011

Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program,…

Patch available
Fix from $1,950 2006-09-27
Inventory Scout MEDIUM 5.0
CVE-2006-5002

Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary …

Patch available
Fix from $1,600 2006-09-27
Lotus Domino Web Access HIGH 7.5
CVE-2006-4763

IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows…

Mitigation only
Fix from $1,950 2006-09-13
Director MEDIUM 5.0
CVE-2006-4681

Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequ…

Fix: after 3.1
Fix from $1,600 2006-09-11
Director MEDIUM 5.0
CVE-2006-4682

Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors …

Fix: after 3.1
Fix from $1,600 2006-09-11
Director MEDIUM 5.0
CVE-2006-4683

IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.

Fix: after 3.1
Fix from $1,600 2006-09-11
Aix HIGH 7.2
CVE-2006-4522

Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

No fix yet
Fix from $1,950 2006-09-01
Aix HIGH 7.2
CVE-2006-4416

Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point t…

Mitigation only
Fix from $1,950 2006-08-28
Aix HIGH 7.5
CVE-2006-4254EPSS 8%

Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2006-08-21
Egatherer HIGH 9.3
CVE-2006-4221EPSS 9%

Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code …

Patch available
Fix from $1,950 2006-08-18
Websphere Application Server MEDIUM 5.0
CVE-2006-4222

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "autho…

Fix: after 6.0.2.11
Fix from $1,600 2006-08-18
Websphere Application Server MEDIUM 5.0
CVE-2006-4223

IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors rel…

Fix: after 6.0.2.11
Fix from $1,600 2006-08-18
Informix Dynamic Database Server HIGH 7.5
CVE-2006-3854

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers t…

No fix yet
Fix from $1,950 2006-08-17
Informix Dynamic Database Server HIGH 7.5
CVE-2006-3860

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands v…

Mitigation only
Fix from $1,950 2006-08-17
Websphere Application Server HIGH 7.5
CVE-2006-4136

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…

Fix: after 6.1.0.0
Fix from $1,950 2006-08-14