Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8223 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1441 1 Ibm 1 Lotus Domino 2026-04-16 5.0 MEDIUM N/A
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).
CVE-2005-0986 1 Ibm 1 Lotus Domino Server 2026-04-16 5.0 MEDIUM N/A
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
CVE-2006-4137 1 Ibm 1 Websphere Application Server 2026-04-16 5.0 MEDIUM N/A
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
CVE-2006-0513 1 Ibm 1 Tivoli Access Manager For E-business 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
CVE-2006-2647 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
CVE-2005-1872 1 Ibm 1 Websphere Application Server 2026-04-16 7.5 HIGH N/A
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
CVE-2001-0319 1 Ibm 3 Net.commerce, Net.commerce Hosting Server, Websphere Commerce Suite 2026-04-16 7.5 HIGH N/A
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
CVE-2001-0051 1 Ibm 1 Db2 Universal Database 2026-04-16 7.5 HIGH N/A
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
CVE-2005-2235 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
CVE-2001-1080 1 Ibm 1 Aix 2026-04-16 10.0 HIGH N/A
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
CVE-1999-0117 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
AIX passwd allows local users to gain root access.
CVE-1999-0138 7 Apple, Digital, Freebsd and 4 more 9 A Ux, Osf 1, Freebsd and 6 more 2026-04-16 7.2 HIGH N/A
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
CVE-2006-3066 1 Ibm 1 Db2 Universal Database 2026-04-16 5.0 MEDIUM N/A
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
CVE-1999-1121 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.
CVE-2003-0837 1 Ibm 1 Db2 Universal Database 2026-04-16 7.5 HIGH N/A
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
CVE-1999-1583 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
CVE-2006-4136 1 Ibm 1 Websphere Application Server 2026-04-16 7.5 HIGH N/A
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
CVE-2001-1311 1 Ibm 1 Lotus Domino R5 2026-04-16 7.5 HIGH N/A
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2004-1372 1 Ibm 1 Db2 Universal Database 2026-04-16 7.2 HIGH N/A
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
CVE-2006-0580 1 Ibm 1 Lotus Domino Server 2026-04-16 5.0 MEDIUM N/A
IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).