Filtered by vendor Ibm
Subscribe
Total
6536 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1731 | 1 Ibm | 1 Os 400 | 2017-07-10 | 2.1 LOW | N/A |
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF. | |||||
CVE-2003-0170 | 1 Ibm | 1 Aix | 2017-07-10 | 10.0 HIGH | N/A |
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors. | |||||
CVE-2003-0178 | 1 Ibm | 1 Lotus Domino Web Server | 2017-07-10 | 10.0 HIGH | N/A |
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation. | |||||
CVE-2003-0179 | 1 Ibm | 2 Lotus Domino Web Server, Lotus Notes Client | 2017-07-10 | 7.5 HIGH | N/A |
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control. | |||||
CVE-2003-0180 | 1 Ibm | 1 Lotus Domino Web Server | 2017-07-10 | 5.0 MEDIUM | N/A |
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form. | |||||
CVE-2003-0181 | 1 Ibm | 1 Lotus Domino Web Server | 2017-07-10 | 5.0 MEDIUM | N/A |
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name. | |||||
CVE-2003-0257 | 1 Ibm | 1 Aix | 2017-07-10 | 7.2 HIGH | N/A |
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges. | |||||
CVE-2003-0285 | 1 Ibm | 1 Aix | 2017-07-10 | 5.0 MEDIUM | N/A |
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail. | |||||
CVE-2003-0696 | 1 Ibm | 1 Aix | 2017-07-10 | 5.0 MEDIUM | N/A |
The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion). | |||||
CVE-2003-0758 | 1 Ibm | 1 Db2 Universal Database | 2017-07-10 | 7.2 HIGH | N/A |
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument. | |||||
CVE-2003-0837 | 1 Ibm | 1 Db2 Universal Database | 2017-07-10 | 7.5 HIGH | N/A |
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command. | |||||
CVE-2000-1215 | 1 Ibm | 1 Lotus Domino | 2017-07-10 | 5.0 MEDIUM | N/A |
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information. | |||||
CVE-2003-1018 | 1 Ibm | 1 Aix | 2017-07-10 | 7.2 HIGH | N/A |
Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors. | |||||
CVE-2003-1049 | 1 Ibm | 1 Db2 Universal Database | 2017-07-10 | 4.6 MEDIUM | N/A |
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files. | |||||
CVE-2003-1050 | 1 Ibm | 1 Db2 | 2017-07-10 | 7.2 HIGH | N/A |
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd. | |||||
CVE-2000-1222 | 1 Ibm | 1 Aix | 2017-07-10 | 7.2 HIGH | N/A |
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program. | |||||
CVE-2003-1051 | 1 Ibm | 1 Db2 | 2017-07-10 | 7.2 HIGH | N/A |
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd. | |||||
CVE-2003-1052 | 1 Ibm | 2 Db2, Db2 Universal Database | 2017-07-10 | 7.2 HIGH | N/A |
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs. | |||||
CVE-2003-1104 | 1 Ibm | 1 Tivoli Firewall Toolbox | 2017-07-10 | 10.0 HIGH | N/A |
Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors. | |||||
CVE-2017-1256 | 1 Ibm | 1 Security Guardium | 2017-07-10 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678 |