Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 7820 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4564 3 Autonomy, Ibm, Symantec 10 Keyview Export Sdk, Keyview Filter Sdk, Keyview Viewer Sdk and 7 more 2025-04-09 9.3 HIGH N/A
Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.
CVE-2007-5957 1 Ibm 1 Informix Dynamic Server 2025-04-09 4.9 MEDIUM N/A
Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 10.00.TC3TL and 11.10.TB4TL on Windows allows attackers to cause a denial of service (application crash) via unspecified SQ_ONASSIST requests.
CVE-2006-5664 1 Ibm 3 Informix Client Sdk, Informix Dynamic Server, Informix I-connect 2025-04-09 4.6 MEDIUM N/A
The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.
CVE-2008-6973 1 Ibm 1 Websphere Commerce 2025-04-09 10.0 HIGH N/A
Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.
CVE-2006-5007 1 Ibm 1 Aix 2025-04-09 4.6 MEDIUM N/A
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
CVE-2008-6106 1 Ibm 2 Workplace For Business Controls And Reporting, Workplace Web Content Management 2025-04-09 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x has unknown impact and remote attack vectors. NOTE: some of these details are obtained from third party information.
CVE-2009-0855 1 Ibm 1 Websphere Application Server 2025-04-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2006-7165 1 Ibm 1 Websphere Application Server 2025-04-09 4.3 MEDIUM N/A
IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."
CVE-2007-5949 1 Ibm 1 Tivoli Service Desk 2025-04-09 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.
CVE-2009-4330 1 Ibm 1 Db2 2025-04-09 7.2 HIGH N/A
Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.
CVE-2009-2090 1 Ibm 1 Websphere Application Server 2025-04-09 5.0 MEDIUM N/A
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.
CVE-2007-0978 1 Ibm 1 Aix 2025-04-09 7.2 HIGH N/A
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
CVE-2009-2092 1 Ibm 1 Websphere Application Server 2025-04-09 7.5 HIGH N/A
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
CVE-2009-0435 1 Ibm 2 Aix, Websphere Application Server 2025-04-09 5.0 MEDIUM N/A
Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.
CVE-2007-3232 1 Ibm 1 Totalstorage Ds400 2025-04-09 10.0 HIGH N/A
The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.
CVE-2008-1998 2 Ibm, Microsoft 2 Db2, Windows 2025-04-09 8.5 HIGH N/A
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
CVE-2007-4474 1 Ibm 2 Domino Web Access, Lotus Domino Web Access 2025-04-09 9.3 HIGH N/A
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
CVE-2007-3264 1 Ibm 1 Websphere Application Server 2025-04-09 10.0 HIGH N/A
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
CVE-2007-1913 8 Apple, Hp, Ibm and 5 more 11 Macos, Hp-ux, Tru64 and 8 more 2025-04-09 5.0 MEDIUM N/A
The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
CVE-2009-2859 1 Ibm 1 Db2 2025-04-09 4.6 MEDIUM N/A
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.