Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 7423 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0037 1 Ibm 1 Lotus Domino Server 2025-04-03 7.5 HIGH N/A
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
CVE-1999-0903 1 Ibm 1 Aix 2025-04-03 7.5 HIGH N/A
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
CVE-2006-0667 1 Ibm 1 Aix 2025-04-03 4.6 MEDIUM N/A
lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
CVE-1999-0429 1 Ibm 1 Lotus Notes 2025-04-03 7.5 HIGH N/A
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
CVE-2002-1167 1 Ibm 1 Websphere Caching Proxy Server 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
CVE-2005-3749 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.
CVE-1999-0208 3 Ibm, Nec, Sgi 5 Aix, Asl Ux 4800, Ews-ux V and 2 more 2025-04-03 10.0 HIGH N/A
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVE-2005-3567 1 Ibm 1 Tivoli Directory Server 2025-04-03 5.8 MEDIUM N/A
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
CVE-1999-0338 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
AIX Licensed Program Product performance tools allow local users to gain root access.
CVE-2001-1440 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
CVE-1999-1589 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
CVE-2004-2281 1 Ibm 1 Lotus Notes 2025-04-03 10.0 HIGH N/A
Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.
CVE-2001-0824 1 Ibm 1 Websphere Application Server 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVE-1999-0131 8 Bsdi, Digital, Eric Allman and 5 more 9 Bsd Os, Osf 1, Sendmail and 6 more 2025-04-03 7.2 HIGH N/A
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
CVE-2003-0898 1 Ibm 1 Db2 Universal Database 2025-04-03 4.6 MEDIUM N/A
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
CVE-2005-2237 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.
CVE-1999-1117 1 Ibm 1 Aix 2025-04-03 2.1 LOW N/A
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
CVE-2002-0905 1 Ibm 1 Informix 2025-04-03 7.2 HIGH N/A
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.
CVE-1999-0024 6 Bsdi, Ibm, Isc and 3 more 12 Bsd Os, Aix, Bind and 9 more 2025-04-03 5.0 MEDIUM N/A
DNS cache poisoning via BIND, by predictable query IDs.
CVE-2006-1384 1 Ibm 1 Tivoli Business Systems Manager 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.