Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,326 CVEs tagged to vendor ibm598 Critical, 1,773 High, 5,208 Medium, 747 Low, 0 Unrated.

CVE-2004-2280

Published Dec 31, 2004

Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java apple…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2281

Published Dec 31, 2004

Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2310

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2311

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new f…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2312

Published Dec 31, 2004

Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2369

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2388

Published Dec 31, 2004

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function an…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2489

Published Dec 31, 2004

Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2526

Published Dec 31, 2004

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2558

Published Dec 31, 2004

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manage…

CVSS 7.5 · High

CVE-2004-2634

Published Dec 31, 2004

The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2663

Published Dec 31, 2004

The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demons…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2667

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2697

Published Dec 31, 2004

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). N…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1329

Published Dec 20, 2004

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0480

Published Dec 6, 2004

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to prov…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0243

Published Nov 23, 2004

AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0253

Published Nov 23, 2004

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0263

Published Nov 23, 2004

PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0828

Published Nov 3, 2004

The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0795

Published Oct 20, 2004

DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1621

Published Oct 18, 2004

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,101-8,125 of 8,326 CVEsPage 325 of 334