Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,230 CVEs tagged to vendor ibm584 Critical, 1,727 High, 5,176 Medium, 743 Low, 0 Unrated.

CVE-2002-0555

Published Jul 3, 2002

IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the deve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0037

Published Apr 22, 2002

Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1621

Published Apr 22, 2002

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1620

Published Apr 1, 2002

Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0086

Published Mar 15, 2002

Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1619

Published Mar 8, 2002

Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1079

Published Feb 13, 2002

create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1504

Published Dec 31, 2001

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user proce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1529

Published Dec 31, 2001

Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1554

Published Dec 31, 2001

IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1557

Published Dec 31, 2001

Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1567

Published Dec 31, 2001

Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1440

Published Dec 21, 2001

Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1189

Published Dec 13, 2001

IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1191

Published Dec 11, 2001

WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0671

Published Dec 6, 2001

Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0824

Published Dec 6, 2001

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0856

Published Dec 6, 2001

Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0924

Published Nov 22, 2001

Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1095

Published Oct 9, 2001

Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1096

Published Oct 9, 2001

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0998

Published Sep 24, 2001

IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1215

Published Sep 19, 2001

The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,126-8,150 of 8,230 CVEsPage 326 of 330