Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ibm Subscribe
Total 6536 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0080 1 Ibm 1 Aix 2016-10-17 2.1 LOW N/A
AIX techlibss allows local users to overwrite files via a symlink attack.
CVE-1999-1531 1 Ibm 1 Homepageprint 2016-10-17 7.5 HIGH N/A
Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.
CVE-1999-1405 1 Ibm 1 Aix 2016-10-17 10.0 HIGH N/A
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
CVE-1999-1408 2 Hp, Ibm 2 Hp-ux, Aix 2016-10-17 2.1 LOW N/A
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
CVE-1999-1414 1 Ibm 1 Netfinity Remote Control 2016-10-17 7.2 HIGH N/A
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.
CVE-1999-1075 1 Ibm 1 Aix 2016-10-17 5.0 MEDIUM N/A
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
CVE-1999-1079 1 Ibm 1 Aix 2016-10-17 4.6 MEDIUM N/A
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
CVE-1999-1013 1 Ibm 1 Aix 2016-10-17 7.2 HIGH N/A
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
CVE-1999-0118 1 Ibm 1 Aix 2016-10-17 7.2 HIGH N/A
AIX infod allows local users to gain root access through an X display.
CVE-1999-0429 1 Ibm 1 Lotus Notes 2016-10-17 7.5 HIGH N/A
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
CVE-1999-0803 1 Ibm 1 Aix Enetwork Firewall 2016-10-17 2.1 LOW N/A
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
CVE-2016-5974 1 Ibm 1 Security Privileged Identity Manager Virtual Appliance 2016-09-28 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
CVE-2001-1095 1 Ibm 1 Aix 2016-09-16 4.6 MEDIUM N/A
Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.
CVE-2009-1174 1 Ibm 1 Websphere Application Server 2016-09-07 10.0 HIGH N/A
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
CVE-2014-8923 1 Ibm 2 Security Identity Manager Active Directory Adapter, Tivoli Identity Manager Active Directory Adapter 2016-08-31 1.9 LOW N/A
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.
CVE-2016-2901 1 Ibm 2 Web Content Manager, Websphere Portal 2016-08-18 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2015-1921 1 Ibm 1 Websphere Portal 2016-08-17 6.4 MEDIUM N/A
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
CVE-2016-0362 1 Ibm 1 Tririga Application Platform 2016-08-11 4.0 MEDIUM 7.7 HIGH
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.
CVE-2015-5038 1 Ibm 1 Connections 2016-08-04 7.8 HIGH 7.5 HIGH
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVE-2015-1900 2 Ibm, Linux 2 Infosphere Datastage, Linux Kernel 2016-08-03 7.2 HIGH N/A
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.