Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,236 CVEs tagged to vendor ibm585 Critical, 1,729 High, 5,179 Medium, 743 Low, 0 Unrated.

CVE-2005-2238

Published Jul 12, 2005

ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2170

Published Jul 11, 2005

The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2175

Published Jul 9, 2005

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2091

Published Jul 5, 2005

IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2073

Published Jun 29, 2005

Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or del…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1872

Published Jun 3, 2005

Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary cod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1405

Published May 3, 2005

HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicio…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1441

Published May 3, 2005

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1442

Published May 3, 2005

Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0240

Published May 2, 2005

Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly han…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0250

Published May 2, 2005

Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0262

Published May 2, 2005

Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0263

Published May 2, 2005

Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0425

Published May 2, 2005

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0539

Published May 2, 2005

Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0899

Published May 2, 2005

AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0986

Published May 2, 2005

NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0991

Published May 2, 2005

RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1025

Published May 2, 2005

The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1037

Published May 2, 2005

Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-1101

Published May 2, 2005

Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via la…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1112

Published May 2, 2005

IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1133

Published May 2, 2005

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1176

Published May 2, 2005

Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive informat…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort
Showing 7,976-8,000 of 8,236 CVEsPage 320 of 330