Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8031 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0835 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2025-04-03 10.0 HIGH N/A
Denial of service in BIND named via malformed SIG records.
CVE-2002-0037 1 Ibm 1 Lotus Domino Server 2025-04-03 7.5 HIGH N/A
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
CVE-2006-2435 1 Ibm 1 Websphere Application Server 2025-04-03 6.4 MEDIUM N/A
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
CVE-1999-0208 3 Ibm, Nec, Sgi 5 Aix, Asl Ux 4800, Ews-ux V and 2 more 2025-04-03 10.0 HIGH N/A
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVE-2001-0671 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
CVE-2001-0573 1 Ibm 1 Aix 2025-04-03 4.6 MEDIUM N/A
lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.
CVE-2001-0552 2 Hp, Ibm 2 Openview Network Node Manager, Tivoli Netview 2025-04-03 10.0 HIGH N/A
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.
CVE-2005-1112 1 Ibm 1 Websphere Application Server 2025-04-03 5.0 MEDIUM N/A
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
CVE-1999-0093 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
CVE-2006-4137 1 Ibm 1 Websphere Application Server 2025-04-03 5.0 MEDIUM N/A
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
CVE-2000-0873 1 Ibm 1 Aix 2025-04-03 2.1 LOW N/A
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
CVE-2004-2490 1 Ibm 2 Informix Dynamic Server, Informix Extended Parallel Server 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.
CVE-2002-1011 1 Ibm 1 Tivoli Management Framework 2025-04-03 7.5 HIGH N/A
Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
CVE-2001-0998 1 Ibm 2 Aix, Hacmp 2025-04-03 5.0 MEDIUM N/A
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
CVE-2001-1557 1 Ibm 1 Aix 2025-04-03 7.5 HIGH N/A
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
CVE-2004-0243 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
CVE-2003-1049 1 Ibm 1 Db2 Universal Database 2025-04-03 4.6 MEDIUM N/A
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.
CVE-2005-1182 1 Ibm 1 Os 400 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.
CVE-2002-0746 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
CVE-1999-1404 1 Ibm 1 Tivoli Opc Tracker Agent 2025-04-03 5.0 MEDIUM N/A
IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.