Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2012-2197
Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5…
Db2
Mitigation only
MEDIUM 5.0
CVE-2012-2194
Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 thro…
Db2
Mitigation only
MEDIUM 5.0
CVE-2012-2196
IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) …
Db2
Mitigation only
MEDIUM 5.0
CVE-2012-2181
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to rea…
Websphere Portal
Mitigation only
HIGH 7.2
CVE-2012-2200
The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma…
Vios
Mitigation only
MEDIUM 6.9
CVE-2012-2179
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Aix
Patch available
MEDIUM 6.5
CVE-2012-2171EPSS 5%
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Ser…
Ds Storage Manager Host Software
after 10.83
HIGH 9.3
CVE-2012-0187
Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a T…
Lotus Expeditor
Mitigation only
MEDIUM 5.0
CVE-2012-0191
The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al…
Lotus Expeditor
Mitigation only
HIGH 9.3
CVE-2012-2174EPSS 38%
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.
Lotus Notes
Mitigation only
HIGH 9.3
CVE-2012-2175EPSS 29%
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote at…
Lotus Inotes
Mitigation only
MEDIUM 5.8
CVE-2012-2159
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…
Security Appscan Source
Mitigation only
MEDIUM 5.0
CVE-2012-2173
The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB …
Security Appscan Source
Mitigation only
HIGH 9.3
CVE-2012-2176EPSS 31%
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote at…
Lotus Quickr
Mitigation only
HIGH 7.5
CVE-2011-1390
SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2…
Rational Clearquest
Mitigation only
HIGH 10.0
CVE-2012-0202EPSS 55%
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers t…
Cognos Tm1
Mitigation only
HIGH 7.2
CVE-2012-0745
The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filt…
Aix
Mitigation only
HIGH 9.3
CVE-2012-0736
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary cod…
Rational Appscan
Mitigation only
HIGH 7.6
CVE-2012-0735
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sens…
Rational Appscan
Mitigation only
HIGH 7.6
CVE-2012-0734
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitiv…
Rational Appscan
Mitigation only
MEDIUM 6.8
CVE-2012-0731
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to…
Rational Appscan
Mitigation only
MEDIUM 6.0
CVE-2012-0729
Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arb…
Rational Appscan
Mitigation only
MEDIUM 6.0
CVE-2012-0730
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hi…
Rational Appscan
Mitigation only
MEDIUM 6.0
CVE-2012-0733
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obta…
Rational Appscan
Mitigation only
MEDIUM 5.8
CVE-2012-0732
The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, whic…
Rational Appscan
Mitigation only
MEDIUM 6.8
CVE-2012-2162
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-k…
Websphere Application Server
after 8.0.0.0
HIGH 9.3
CVE-2012-0708EPSS 31%
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1…
Rational Clearquest
Mitigation only
MEDIUM 6.4
CVE-2012-0726
The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allow…
Tivoli Directory Server
after 6.3.0
MEDIUM 5.0
CVE-2012-0743
IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged sear…
Tivoli Directory Server
after 6.3.0
MEDIUM 5.0
CVE-2012-1837
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOn…
Tivoli Endpoint Manager
after 8.1