Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Total 8223 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2312 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
CVE-1999-0101 1 Ibm 1 Aix 2026-04-16 10.0 HIGH N/A
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
CVE-2006-2435 1 Ibm 1 Websphere Application Server 2026-04-16 6.4 MEDIUM N/A
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
CVE-2006-4522 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
CVE-2005-2618 2 Autonomy, Ibm 4 Keyview Export Sdk, Keyview Filter Sdk, Keyview Viewer Sdk and 1 more 2026-04-16 9.3 HIGH N/A
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).
CVE-2004-0263 2 Apache, Ibm 2 Http Server, Http Server 2026-04-16 5.0 MEDIUM N/A
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
CVE-2002-1687 1 Ibm 1 Aix 2026-04-16 2.1 LOW N/A
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
CVE-1999-0091 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Buffer overflow in AIX writesrv command allows local users to obtain root access.
CVE-2001-0487 1 Ibm 1 Aix Snmp 2026-04-16 5.0 MEDIUM N/A
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
CVE-1999-0694 1 Ibm 1 Aix 2026-04-16 2.1 LOW N/A
Denial of service in AIX ptrace system call allows local users to crash the system.
CVE-2004-2388 1 Ibm 1 Aix 2026-04-16 10.0 HIGH N/A
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
CVE-2003-1527 2 Ibm, Iss 2 Internet Security Systems Blackice Defender, Blackice Server Protection 2026-04-16 4.3 MEDIUM N/A
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
CVE-2004-2697 1 Ibm 1 Aix 2026-04-16 6.9 MEDIUM N/A
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
CVE-2000-1121 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
CVE-2003-0898 1 Ibm 1 Db2 Universal Database 2026-04-16 4.6 MEDIUM N/A
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
CVE-2006-2432 1 Ibm 1 Websphere Application Server 2026-04-16 7.5 HIGH N/A
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
CVE-2005-0991 1 Ibm 1 Aix 2026-04-16 2.1 LOW N/A
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
CVE-2002-1203 1 Ibm 1 Secureway Firewall 2026-04-16 5.0 MEDIUM N/A
IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.
CVE-2003-0170 1 Ibm 1 Aix 2026-04-16 10.0 HIGH N/A
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.
CVE-1999-1531 1 Ibm 1 Homepageprint 2026-04-16 7.5 HIGH N/A
Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.