Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8031 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4273 1 Ibm 1 Aix 2025-04-03 2.1 LOW N/A
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
CVE-2005-4738 1 Ibm 1 Db2 Universal Database 2025-04-03 6.5 MEDIUM N/A
IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.
CVE-1999-0040 7 Bsdi, Freebsd, Hp and 4 more 10 Bsd Os, Freebsd, Hp-ux and 7 more 2025-04-03 7.2 HIGH N/A
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
CVE-1999-1408 2 Hp, Ibm 2 Hp-ux, Aix 2025-04-03 2.1 LOW N/A
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
CVE-2002-2372 1 Ibm 2 Infoprint, Infoprint 21 2025-04-03 5.0 MEDIUM N/A
The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.
CVE-2001-1189 1 Ibm 1 Websphere Application Server 2025-04-03 4.6 MEDIUM N/A
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
CVE-2002-1168 1 Ibm 1 Websphere Caching Proxy Server 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.
CVE-2000-0761 1 Ibm 1 Os2 Ftp Server 2025-04-03 5.0 MEDIUM N/A
OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.
CVE-2002-1620 1 Ibm 1 Aix Parallel Systems Support Programs 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection.
CVE-2006-0663 1 Ibm 1 Lotus Domino Inotes Client 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
CVE-2005-4819 1 Ibm 1 Lotus Domino 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-1999-0117 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
AIX passwd allows local users to gain root access.
CVE-2001-1554 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
CVE-2002-0554 1 Ibm 1 Informix Web Datablade 2025-04-03 7.5 HIGH N/A
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.
CVE-2001-1504 1 Ibm 1 Lotus Notes 2025-04-03 7.5 HIGH N/A
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
CVE-2000-0249 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
CVE-2002-0679 6 Caldera, Compaq, Hp and 3 more 8 Openunix, Unixware, Tru64 and 5 more 2025-04-03 10.0 HIGH N/A
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
CVE-2003-0578 1 Ibm 1 U2 Universe 2025-04-03 4.6 MEDIUM 7.8 HIGH
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
CVE-2003-0181 1 Ibm 1 Lotus Domino Web Server 2025-04-03 5.0 MEDIUM N/A
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
CVE-1999-0337 1 Ibm 1 Aix 2025-04-03 7.5 HIGH N/A
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.