Skip to main content

Vendor archive

ibm CVEs

Beta · best-effort

8,236 CVEs tagged to vendor ibm585 Critical, 1,729 High, 5,179 Medium, 743 Low, 0 Unrated.

CVE-2005-1182

Published May 2, 2005

Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of servi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1238

Published May 2, 2005

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0417

Published Apr 27, 2005

Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0261

Published Feb 10, 2005

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1028

Published Jan 10, 2005

Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to p…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1054

Published Jan 10, 2005

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1330

Published Dec 31, 2004

Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1442

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2270

Published Dec 31, 2004

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2280

Published Dec 31, 2004

Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java apple…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2281

Published Dec 31, 2004

Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2310

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2311

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new f…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2312

Published Dec 31, 2004

Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2369

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2388

Published Dec 31, 2004

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function an…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2489

Published Dec 31, 2004

Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2526

Published Dec 31, 2004

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2558

Published Dec 31, 2004

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manage…

CVSS 7.5 · High

CVE-2004-2634

Published Dec 31, 2004

The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2663

Published Dec 31, 2004

The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demons…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 8,001-8,025 of 8,236 CVEsPage 321 of 330