Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2012-1797
IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.
Db2
Mitigation only
HIGH 7.5
CVE-2012-0711
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through…
Db2
Mitigation only
HIGH 7.2
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via…
Db2
Mitigation only
MEDIUM 5.0
CVE-2012-0710
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a…
Db2
Mitigation only
MEDIUM 6.5
CVE-2011-4816
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset M…
Maximo Asset Management
Mitigation only
MEDIUM 6.8
CVE-2011-1397
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, …
Maximo Asset Management
Mitigation only
MEDIUM 5.0
CVE-2011-1394
IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Servi…
Maximo Asset Management
Mitigation only
HIGH 9.3
CVE-2012-0198EPSS 37%
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Softw…
Tivoli Provisioning Manager Express For Software Distribution
Mitigation only
HIGH 7.5
CVE-2012-0199
Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute a…
Tivoli Provisioning Manager Express For Software Distribution
Mitigation only
HIGH 7.8
CVE-2011-1385
IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packe…
Vios
Patch available
HIGH 9.3
CVE-2012-0201EPSS 37%
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote a…
Personal Communications
No fix yet
HIGH 7.1
CVE-2012-0194
The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of serv…
Aix
Patch available
HIGH 9.3
CVE-2012-0192EPSS 5%
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute…
Lotus Symphony
after 3.0.0.3
MEDIUM 5.0
CVE-2012-0193
IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo…
Websphere Application Server
Patch available
HIGH 10.0
CVE-2011-1389EPSS 7%
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Serv…
Rational License Key Server
Patch available
HIGH 9.3
CVE-2012-0189
Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVIEW6.ocx in IBM SPSS SamplePow…
Spss Samplepower
Mitigation only
HIGH 9.3
CVE-2012-0190
Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Colle…
Spss Data Collection
Mitigation only
HIGH 9.3
CVE-2012-0188
Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.…
Spss Data Collection
Mitigation only
HIGH 10.0
CVE-2011-1377
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly…
Websphere Application Server
Mitigation only
HIGH 7.8
CVE-2011-1393
Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause…
Lotus Domino
after 8.5.2
HIGH 7.5
CVE-2011-4668
IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program us…
Tivoli Netcool\/reporter
Mitigation only
MEDIUM 6.8
CVE-2011-1372
The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obt…
Ts3100 Tape Library Firmware
Mitigation only
MEDIUM 5.0
CVE-2011-4435
The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent …
Db2 Tools For Z\/os
Mitigation only
HIGH 9.3
CVE-2011-1367
Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote …
Rational Appscan
Mitigation only
HIGH 8.8
CVE-2011-1366
Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0…
Rational Appscan
Mitigation only
MEDIUM 5.0
CVE-2009-2747
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and…
Websphere Application Server
Mitigation only
MEDIUM 5.0
CVE-2011-1368
The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which …
Websphere Application Server
Mitigation only
MEDIUM 5.0
CVE-2011-1370
The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authen…
Lotus Sametime
Mitigation only
MEDIUM 6.9
CVE-2011-4061
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring f…
Db2
No fix yet
HIGH 10.0
CVE-2011-3577
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which…
Websphere Commerce
Mitigation only