Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.6 CVE-2010-0919EPSS 6% Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, … Domino Web Access after 229.271 Fix from $1,9502010-03-03 MEDIUM 6.8 CVE-2010-0921 Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote … Lotus Inotes after 229.271 Fix from $1,6002010-03-03 MEDIUM 6.8 CVE-2010-0715 Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Managem… Websphere Portal Patch available Fix from $1,6002010-02-26 MEDIUM 5.0 CVE-2010-0563 The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configur… Websphere Application Server Patch available Fix from $1,6002010-02-08 HIGH 7.5 CVE-2010-0557EPSS 51% IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging ha… Cognos Express Mitigation only Fix from $1,9502010-02-05 MEDIUM 5.5 CVE-2009-2750 IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration properties, which allows remote authen… Websphere Service Registry And Repository Patch available Fix from $1,6002010-02-04 MEDIUM 5.0 CVE-2010-0472 kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) … Db2 No fix yet Fix from $1,6002010-02-02 MEDIUM 6.5 CVE-2010-0462EPSS 8% Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified imp… Db2 No fix yet Fix from $1,6002010-01-28 HIGH 10.0 CVE-2010-0358 Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and pos… Lotus Domino Mitigation only Fix from $1,9502010-01-20 MEDIUM 5.0 CVE-2010-0312 The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL p… Tivoli Directory Server No fix yet Fix from $1,6002010-01-14 HIGH 10.0 CVE-2009-4594 Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, a… Lotus Inotes after 229.111 Fix from $1,9502010-01-09 HIGH 10.0 CVE-2010-0274 Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino … Lotus Inotes after 229.231 Fix from $1,9502010-01-09 HIGH 10.0 CVE-2010-0275 Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in t… Lotus Inotes after 229.231 Fix from $1,9502010-01-09 HIGH 10.0 CVE-2010-0276 IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyw… Domino Web Access No fix yet Fix from $1,9502010-01-09 MEDIUM 6.5 CVE-2009-4438 The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege require… Db2 Patch available Fix from $1,6002009-12-28 HIGH 7.2 CVE-2009-4361 Multiple buffer overflows in qoslist in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges vi… Aix Mitigation only Fix from $1,9502009-12-21 HIGH 7.2 CVE-2009-4362 Multiple buffer overflows in qosmod in IBM AIX 6.1 allow local users to cause a denial of service (application crash) or possibly gain privileges via… Aix Mitigation only Fix from $1,9502009-12-21 MEDIUM 5.0 CVE-2009-4357 CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might al… Rational Clearcase after 7.1 Fix from $1,6002009-12-18 HIGH 10.0 CVE-2009-4335 Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and… Db2 Patch available Fix from $1,9502009-12-16 HIGH 7.5 CVE-2009-4333 The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st… Db2 Patch available Fix from $1,9502009-12-16 HIGH 7.2 CVE-2009-4330 Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors. Db2 Patch available Fix from $1,9502009-12-16 HIGH 7.2 CVE-2009-4331 The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and a… Db2 Patch available Fix from $1,9502009-12-16 MEDIUM 6.4 CVE-2009-4325 The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified point… Db2 Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4327 The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a c… Db2 Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4332 db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer… Db2 Patch available Fix from $1,6002009-12-16 HIGH 10.0 CVE-2009-4240 Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unkno… Infosphere Information Server No fix yet Fix from $1,9502009-12-09 MEDIUM 6.4 CVE-2009-2749 Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session value… Websphere Application Server after 1.0 Fix from $1,6002009-12-08 HIGH 7.5 CVE-2009-4153 Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to t… Websphere Portal Patch available Fix from $1,9502009-12-02 MEDIUM 6.8 CVE-2009-2746 Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0… Websphere Application Server Patch available Fix from $1,6002009-11-16 HIGH 10.0 CVE-2009-3935 Multiple unspecified vulnerabilities in the Advanced Management Module firmware before 2.50G for the IBM BladeCenter T 8720-2xx and 8730-2xx have unk… Advanced Management Module Firmware after 2.50c Fix from $1,9502009-11-12