Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aix HIGH 7.2
CVE-2005-2235

Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line ar…

Patch available
Fix from $1,950 2005-07-12
Aix HIGH 7.2
CVE-2005-2236

Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via…

No fix yet
Fix from $1,950 2005-07-12
Tivoli Management Framework MEDIUM 5.0
CVE-2005-2170

The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connectio…

Patch available
Fix from $1,600 2005-07-11
Lotus Notes MEDIUM 5.0
CVE-2005-2175EPSS 5%

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it ea…

Mitigation only
Fix from $1,600 2005-07-09
Websphere Application Server HIGH 7.5
CVE-2005-1872

Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote atta…

Patch available
Fix from $1,950 2005-06-03
Lotus Domino MEDIUM 5.0
CVE-2005-1441

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the No…

Patch available
Fix from $1,600 2005-05-03
Aix HIGH 10.0
CVE-2005-1037

Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.

Patch available
Fix from $1,950 2005-05-02
Lotus Domino Server HIGH 7.5
CVE-2005-1101

Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly…

Patch available
Fix from $1,950 2005-05-02
Iseries As 400 HIGH 7.5
CVE-2005-1238

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write ar…

Mitigation only
Fix from $1,950 2005-05-02
Aix HIGH 7.2
CVE-2005-0240

Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argum…

Mitigation only
Fix from $1,950 2005-05-02
Aix HIGH 7.2
CVE-2005-0250

Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in …

Patch available
Fix from $1,950 2005-05-02
Aix HIGH 7.2
CVE-2005-0262

Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

Patch available
Fix from $1,950 2005-05-02
Aix HIGH 7.2
CVE-2005-0263

Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

Patch available
Fix from $1,950 2005-05-02
Websphere Application Server MEDIUM 5.0
CVE-2005-0425

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source cod…

Patch available
Fix from $1,600 2005-05-02
Lotus Domino Server MEDIUM 5.0
CVE-2005-0986EPSS 7%

NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2005-05-02
Iseries As 400 MEDIUM 5.0
CVE-2005-1025

The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and t…

No fix yet
Fix from $1,600 2005-05-02
Websphere Application Server MEDIUM 5.0
CVE-2005-1112EPSS 9%

IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code…

Mitigation only
Fix from $1,600 2005-05-02
Iseries As 400 MEDIUM 5.0
CVE-2005-1133

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid …

Mitigation only
Fix from $1,600 2005-05-02
Os 400 MEDIUM 5.0
CVE-2005-1182

Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attack…

Mitigation only
Fix from $1,600 2005-05-02
Db2 Universal Database HIGH 10.0
CVE-2005-0417

Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosu…

Patch available
Fix from $1,950 2005-04-27
Aix HIGH 7.2
CVE-2004-1028

Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the …

Mitigation only
Fix from $1,950 2005-01-10
Aix HIGH 7.2
CVE-2004-1054

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH env…

Mitigation only
Fix from $1,950 2005-01-10
Lotus Notes HIGH 10.0
CVE-2004-2281

Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java…

Patch available
Fix from $1,950 2004-12-31
Aix HIGH 10.0
CVE-2004-2388

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten b…

Patch available
Fix from $1,950 2004-12-31
Tivoli Access Manager For E Business HIGH 7.5
CVE-2004-2558

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solu…

Patch available
Fix from $1,950 2004-12-31
Egatherer HIGH 7.5
CVE-2004-2663

The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files wit…

Patch available
Fix from $1,950 2004-12-31
Aix HIGH 7.2
CVE-2004-1330

Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.

Patch available
Fix from $1,950 2004-12-31
Parallel Environment HIGH 7.2
CVE-2004-2270

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the …

Patch available
Fix from $1,950 2004-12-31
Aix HIGH 7.2
CVE-2004-2312

Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

Patch available
Fix from $1,950 2004-12-31
Aix MEDIUM 6.9
CVE-2004-2697

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a comman…

No fix yet
Fix from $1,600 2004-12-31