Filtered by vendor Ibm
Subscribe
Total
6536 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2000-0080 | 1 Ibm | 1 Aix | 2016-10-17 | 2.1 LOW | N/A |
AIX techlibss allows local users to overwrite files via a symlink attack. | |||||
CVE-1999-1531 | 1 Ibm | 1 Homepageprint | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag. | |||||
CVE-1999-1405 | 1 Ibm | 1 Aix | 2016-10-17 | 10.0 HIGH | N/A |
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a. | |||||
CVE-1999-1408 | 2 Hp, Ibm | 2 Hp-ux, Aix | 2016-10-17 | 2.1 LOW | N/A |
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. | |||||
CVE-1999-1414 | 1 Ibm | 1 Netfinity Remote Control | 2016-10-17 | 7.2 HIGH | N/A |
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges. | |||||
CVE-1999-1075 | 1 Ibm | 1 Aix | 2016-10-17 | 5.0 MEDIUM | N/A |
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd. | |||||
CVE-1999-1079 | 1 Ibm | 1 Aix | 2016-10-17 | 4.6 MEDIUM | N/A |
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. | |||||
CVE-1999-1013 | 1 Ibm | 1 Aix | 2016-10-17 | 7.2 HIGH | N/A |
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file. | |||||
CVE-1999-0118 | 1 Ibm | 1 Aix | 2016-10-17 | 7.2 HIGH | N/A |
AIX infod allows local users to gain root access through an X display. | |||||
CVE-1999-0429 | 1 Ibm | 1 Lotus Notes | 2016-10-17 | 7.5 HIGH | N/A |
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference. | |||||
CVE-1999-0803 | 1 Ibm | 1 Aix Enetwork Firewall | 2016-10-17 | 2.1 LOW | N/A |
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. | |||||
CVE-2016-5974 | 1 Ibm | 1 Security Privileged Identity Manager Virtual Appliance | 2016-09-28 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string. | |||||
CVE-2001-1095 | 1 Ibm | 1 Aix | 2016-09-16 | 4.6 MEDIUM | N/A |
Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter. | |||||
CVE-2009-1174 | 1 Ibm | 1 Websphere Application Server | 2016-09-07 | 10.0 HIGH | N/A |
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors. | |||||
CVE-2014-8923 | 1 Ibm | 2 Security Identity Manager Active Directory Adapter, Tivoli Identity Manager Active Directory Adapter | 2016-08-31 | 1.9 LOW | N/A |
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file. | |||||
CVE-2016-2901 | 1 Ibm | 2 Web Content Manager, Websphere Portal | 2016-08-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |||||
CVE-2015-1921 | 1 Ibm | 1 Websphere Portal | 2016-08-17 | 6.4 MEDIUM | N/A |
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | |||||
CVE-2016-0362 | 1 Ibm | 1 Tririga Application Platform | 2016-08-11 | 4.0 MEDIUM | 7.7 HIGH |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service. | |||||
CVE-2015-5038 | 1 Ibm | 1 Connections | 2016-08-04 | 7.8 HIGH | 7.5 HIGH |
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |||||
CVE-2015-1900 | 2 Ibm, Linux | 2 Infosphere Datastage, Linux Kernel | 2016-08-03 | 7.2 HIGH | N/A |
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors. |