Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 7776 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1324 1 Ibm 1 Rational Engineering Lifecycle Manager 2017-10-10 3.5 LOW 5.4 MEDIUM
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975.
CVE-2004-0263 2 Apache, Ibm 2 Http Server, Http Server 2017-10-10 5.0 MEDIUM N/A
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
CVE-1999-1121 1 Ibm 1 Aix 2017-10-10 7.2 HIGH N/A
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
CVE-2001-0998 1 Ibm 2 Aix, Hacmp 2017-10-10 5.0 MEDIUM N/A
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
CVE-1999-1117 1 Ibm 1 Aix 2017-10-10 2.1 LOW N/A
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
CVE-2001-1079 1 Ibm 1 Aix 2017-10-10 3.6 LOW N/A
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
CVE-1999-1208 1 Ibm 1 Aix 2017-10-10 7.2 HIGH N/A
Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
CVE-2000-0677 1 Ibm 1 Net.data 2017-10-10 10.0 HIGH N/A
Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.
CVE-2000-1119 1 Ibm 1 Aix 2017-10-10 4.6 MEDIUM N/A
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
CVE-2000-0873 1 Ibm 1 Aix 2017-10-10 2.1 LOW N/A
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
CVE-2000-0652 1 Ibm 1 Websphere Application Server 2017-10-10 5.0 MEDIUM N/A
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
CVE-2000-0848 1 Ibm 1 Websphere Application Server 2017-10-10 10.0 HIGH N/A
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
CVE-2000-1121 1 Ibm 1 Aix 2017-10-10 7.2 HIGH N/A
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
CVE-2001-0982 1 Ibm 1 Tivoli Secureway Policy Director 2017-10-10 5.0 MEDIUM N/A
Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.
CVE-2000-1124 1 Ibm 1 Aix 2017-10-10 7.2 HIGH N/A
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
CVE-2000-1120 1 Ibm 1 Aix 2017-10-10 7.2 HIGH N/A
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
CVE-1999-1486 1 Ibm 1 Aix 2017-10-10 1.2 LOW N/A
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.
CVE-1999-1119 1 Ibm 1 Aix 2017-10-10 10.0 HIGH N/A
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
CVE-2001-0962 1 Ibm 2 Websphere Application Server, Websphere Commerce Suite 2017-10-10 7.5 HIGH N/A
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
CVE-1999-0718 1 Ibm 1 Gina 2017-10-10 6.2 MEDIUM N/A
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.