Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lotus Domino MEDIUM 5.0
CVE-2000-1215

The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of…

Mitigation only
Fix from $1,600 2001-09-19
Aix HIGH 10.0
CVE-2001-1061

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

No fix yet
Fix from $1,950 2001-08-31
Http Server Ssl Module Common HIGH 7.2
CVE-2000-1202

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories…

Patch available
Fix from $1,950 2001-08-31
Aix HIGH 7.2
CVE-2001-0533

Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

Mitigation only
Fix from $1,950 2001-08-14
Tivoli Secureway Policy Director MEDIUM 5.0
CVE-2001-0982

Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directo…

Patch available
Fix from $1,600 2001-07-23
Lotus Notes HIGH 7.5
CVE-2000-0891

A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message t…

Fix: after 5.02
Fix from $1,950 2001-07-21
Alphaworks Tftp Server HIGH 7.5
CVE-2001-1265

Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary fil…

No fix yet
Fix from $1,950 2001-07-20
Secureway Directory HIGH 7.5
CVE-2001-1309EPSS 5%

Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstra…

Mitigation only
Fix from $1,950 2001-07-16
Secureway Directory HIGH 7.5
CVE-2001-1310

IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L …

Patch available
Fix from $1,950 2001-07-16
Lotus Domino R5 HIGH 7.5
CVE-2001-1311EPSS 7%

Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a…

Fix: after 5.0.7a
Fix from $1,950 2001-07-16
Lotus Domino R5 HIGH 7.5
CVE-2001-1312

Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbi…

Fix: after 5.0.7a
Fix from $1,950 2001-07-16
Lotus Domino R5 HIGH 7.5
CVE-2001-1313

Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous pac…

Fix: after 5.0.7a
Fix from $1,950 2001-07-16
Db2 Universal Database MEDIUM 5.0
CVE-2001-1143

IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port…

Mitigation only
Fix from $1,600 2001-07-11
Visualage For Java MEDIUM 6.8
CVE-2001-1441

Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via th…

No fix yet
Fix from $1,600 2001-07-02
Net.commerce MEDIUM 5.0
CVE-2001-0389

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEX…

No fix yet
Fix from $1,600 2001-07-02
Net.commerce MEDIUM 5.0
CVE-2001-0390EPSS 5%

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %…

No fix yet
Fix from $1,600 2001-07-02
High Availability Cluster Multiprocessing MEDIUM 5.0
CVE-2001-0472

Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an…

Patch available
Fix from $1,600 2001-06-27
Aix Snmp MEDIUM 5.0
CVE-2001-0487

AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.

Mitigation only
Fix from $1,600 2001-06-27
Aix HIGH 10.0
CVE-2001-1080EPSS 6%

diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privile…

Mitigation only
Fix from $1,950 2001-06-19
Websphere Commerce Suite MEDIUM 5.0
CVE-2001-0446

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to…

Mitigation only
Fix from $1,600 2001-06-18
Aix HIGH 7.2
CVE-2001-1329

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

No fix yet
Fix from $1,950 2001-06-11
Aix HIGH 7.2
CVE-2001-1330

Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

No fix yet
Fix from $1,950 2001-06-11
Websphere Plugin MEDIUM 5.0
CVE-2001-0312

IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a hos…

Patch available
Fix from $1,600 2001-06-02
Net.commerce HIGH 7.5
CVE-2001-0319EPSS 7%

orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of th…

No fix yet
Fix from $1,950 2001-05-03
HTTP Server MEDIUM 5.0
CVE-2001-0122

Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote att…

Patch available
Fix from $1,600 2001-03-13
Gina MEDIUM 6.2
CVE-1999-0718

IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapp…

Patch available
Fix from $1,600 2001-03-12
Lotus Domino Server MEDIUM 5.0
CVE-1999-0729

Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.

No fix yet
Fix from $1,600 2001-03-12
Db2 Universal Database HIGH 7.5
CVE-2001-0051

IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the …

No fix yet
Fix from $1,950 2001-02-16
Lotus Notes HIGH 7.5
CVE-2000-1138

Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker t…

Fix: after 5.0.5
Fix from $1,950 2001-01-09
HTTP Server HIGH 7.5
CVE-2000-1168

IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET r…

Mitigation only
Fix from $1,950 2001-01-09