Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2007-3232
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator acco…
Totalstorage Ds400
Mitigation only
HIGH 9.3
CVE-2007-0068
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote au…
Lotus Domino
Mitigation only
HIGH 7.8
CVE-2007-0067EPSS 14%
Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of…
Lotus Domino Web Server
Patch available
MEDIUM 6.6
CVE-2007-2996
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain …
Aix
Patch available
HIGH 10.0
CVE-2007-2582EPSS 27%
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary c…
Db2
after 9.0
HIGH 10.0
CVE-2006-7198
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and att…
Websphere Application Server
after 6.0.2.11
HIGH 10.0
CVE-2007-2137EPSS 8%
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitor…
Tivoli Monitoring Express
Patch available
HIGH 7.5
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack …
Websphere Application Server
after 6.1.0.1
MEDIUM 5.0
CVE-2007-1944
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vec…
Websphere Application Server
after 6.1.0.1
HIGH 10.0
CVE-2007-1868EPSS 59%
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTT…
Tivoli Provisioning Manager Os Deployment
Patch available
HIGH 7.2
CVE-2007-1798
Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary co…
Aix
Mitigation only
HIGH 9.3
CVE-2007-1784
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL librari…
Lotus Sametime
after 7.0
HIGH 7.8
CVE-2007-1739
Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of …
Lotus Domino
No fix yet
HIGH 10.0
CVE-2007-1675EPSS 61%
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 all…
Lotus Domino
Patch available
HIGH 7.5
CVE-2007-1608
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and c…
Websphere Application Server
after 6.0.2.15
MEDIUM 5.0
CVE-2006-7166
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a s…
Websphere Application Server
Patch available
HIGH 7.2
CVE-2007-1086
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecif…
Db2 Universal Database
Patch available
HIGH 7.2
CVE-2007-1087
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arb…
Db2
Patch available
HIGH 7.2
CVE-2007-1088
Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long str…
Db2
Patch available
HIGH 7.2
CVE-2007-1089
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL…
Db2 Universal Database
after 9.1
HIGH 7.2
CVE-2007-0978
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
Aix
Mitigation only
HIGH 7.1
CVE-2007-0977EPSS 19%
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible thr…
Lotus Domino
No fix yet
HIGH 7.5
CVE-2007-0618
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving a…
Aix
Patch available
MEDIUM 5.0
CVE-2007-0442
Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-T…
Os 400
Mitigation only
HIGH 10.0
CVE-2006-6836
Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.
Os 400
No fix yet
MEDIUM 5.0
CVE-2006-6914
Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspec…
Aix
Patch available
HIGH 10.0
CVE-2006-6636
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impac…
Websphere Application Server
Patch available
MEDIUM 5.0
CVE-2006-6637
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true …
Websphere Application Server
Patch available
MEDIUM 5.0
CVE-2006-6638
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereferenc…
Db2 Universal Database
Patch available
HIGH 7.5
CVE-2006-6537
IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, rela…
Websphere Host On Demand
Mitigation only