Vulnerability index

Browse CVEs

6,336 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2007-3232 The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator acco… Totalstorage Ds400 Mitigation only Fix from $1,9502007-06-15 HIGH 9.3 CVE-2007-0068 IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote au… Lotus Domino Mitigation only Fix from $1,9502007-06-06 HIGH 7.8 CVE-2007-0067EPSS 14% Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of… Lotus Domino Web Server Patch available Fix from $1,9502007-06-06 MEDIUM 6.6 CVE-2007-2996 Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain … Aix Patch available Fix from $1,6002007-06-04 HIGH 10.0 CVE-2007-2582EPSS 27% Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary c… Db2 after 9.0 Fix from $1,9502007-05-10 HIGH 10.0 CVE-2006-7198 Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and att… Websphere Application Server after 6.0.2.11 Fix from $1,9502007-04-30 HIGH 10.0 CVE-2007-2137EPSS 8% Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitor… Tivoli Monitoring Express Patch available Fix from $1,9502007-04-22 HIGH 7.5 CVE-2007-1945 Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack … Websphere Application Server after 6.1.0.1 Fix from $1,9502007-04-11 MEDIUM 5.0 CVE-2007-1944 The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vec… Websphere Application Server after 6.1.0.1 Fix from $1,6002007-04-11 HIGH 10.0 CVE-2007-1868EPSS 59% The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTT… Tivoli Provisioning Manager Os Deployment Patch available Fix from $1,9502007-04-04 HIGH 7.2 CVE-2007-1798 Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary co… Aix Mitigation only Fix from $1,9502007-04-02 HIGH 9.3 CVE-2007-1784 The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL librari… Lotus Sametime after 7.0 Fix from $1,9502007-03-31 HIGH 7.8 CVE-2007-1739 Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of … Lotus Domino No fix yet Fix from $1,9502007-03-28 HIGH 10.0 CVE-2007-1675EPSS 61% Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 all… Lotus Domino Patch available Fix from $1,9502007-03-28 HIGH 7.5 CVE-2007-1608 CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and c… Websphere Application Server after 6.0.2.15 Fix from $1,9502007-03-22 MEDIUM 5.0 CVE-2006-7166 IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a s… Websphere Application Server Patch available Fix from $1,6002007-03-20 HIGH 7.2 CVE-2007-1086 Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecif… Db2 Universal Database Patch available Fix from $1,9502007-02-23 HIGH 7.2 CVE-2007-1087 IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arb… Db2 Patch available Fix from $1,9502007-02-23 HIGH 7.2 CVE-2007-1088 Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long str… Db2 Patch available Fix from $1,9502007-02-23 HIGH 7.2 CVE-2007-1089 IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL… Db2 Universal Database after 9.1 Fix from $1,9502007-02-23 HIGH 7.2 CVE-2007-0978 Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data. Aix Mitigation only Fix from $1,9502007-02-16 HIGH 7.1 CVE-2007-0977EPSS 19% IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible thr… Lotus Domino No fix yet Fix from $1,9502007-02-16 HIGH 7.5 CVE-2007-0618 Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving a… Aix Patch available Fix from $1,9502007-01-31 MEDIUM 5.0 CVE-2007-0442 Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-T… Os 400 Mitigation only Fix from $1,6002007-01-23 HIGH 10.0 CVE-2006-6836 Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing. Os 400 No fix yet Fix from $1,9502006-12-31 MEDIUM 5.0 CVE-2006-6914 Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspec… Aix Patch available Fix from $1,6002006-12-31 HIGH 10.0 CVE-2006-6636 Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impac… Websphere Application Server Patch available Fix from $1,9502006-12-19 MEDIUM 5.0 CVE-2006-6637 The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true … Websphere Application Server Patch available Fix from $1,6002006-12-19 MEDIUM 5.0 CVE-2006-6638 IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereferenc… Db2 Universal Database Patch available Fix from $1,6002006-12-19 HIGH 7.5 CVE-2006-6537 IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, rela… Websphere Host On Demand Mitigation only Fix from $1,9502006-12-14