Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 7423 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0051 1 Ibm 1 Db2 Universal Database 2025-04-03 7.5 HIGH N/A
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
CVE-1999-0018 3 Ibm, Sgi, Sun 4 Aix, Irix, Solaris and 1 more 2025-04-03 10.0 HIGH N/A
Buffer overflow in statd allows root privileges.
CVE-2005-4863 1 Ibm 1 Db2 Universal Database 2025-04-03 7.2 HIGH N/A
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.
CVE-2005-2618 2 Autonomy, Ibm 4 Keyview Export Sdk, Keyview Filter Sdk, Keyview Viewer Sdk and 1 more 2025-04-03 9.3 HIGH N/A
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).
CVE-2006-4222 1 Ibm 1 Websphere Application Server 2025-04-03 5.0 MEDIUM N/A
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.
CVE-2005-1133 1 Ibm 1 Iseries As 400 2025-04-03 5.0 MEDIUM N/A
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
CVE-2003-1447 1 Ibm 1 Websphere Application Server 2025-04-03 1.9 LOW N/A
IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
CVE-2003-0784 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
CVE-2000-0441 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.
CVE-1999-0064 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Buffer overflow in AIX lquerylv program gives root access to local users.
CVE-2000-1120 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
CVE-1999-0086 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
AIX routed allows remote users to modify sensitive files.
CVE-2005-1405 1 Ibm 1 Lotus Notes 2025-04-03 2.1 LOW N/A
HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.
CVE-2002-1690 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
CVE-2002-1583 1 Ibm 1 Db2 Universal Database 2025-04-03 7.2 HIGH N/A
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.
CVE-1999-0101 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
CVE-2000-1138 1 Ibm 1 Lotus Notes 2025-04-03 7.5 HIGH N/A
Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.
CVE-1999-0094 1 Ibm 1 Aix 2025-04-03 4.6 MEDIUM N/A
AIX piodmgrsu command allows local users to gain additional group privileges.
CVE-2002-1201 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.
CVE-2001-0389 1 Ibm 2 Net.commerce, Websphere Application Server 2025-04-03 5.0 MEDIUM N/A
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.