← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buil...Show more
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and So...Show more
Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly in...Show more
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
1.9 LOW· v2
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3)...Show more
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/t...Show more
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Aug 18, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.
1Ibm
1Rational Clearquest
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
1Ibm
1Aix
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
1Ibm
1Aix
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
1Ibm
1Aix
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users in the system group to gain root privileges via unspecified vectors involving the (1) chpath, (2) rmpath, and (3) devinstall programs in bos.rte.methods.
1Ibm
1Lotus Notes
Apr 23, 2026
Aug 13, 2007
N/A· v4
N/A· v3
3.5 LOW· v2
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a dif...Show more
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.Show less
1Ibm
1Aix
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
AIX 5.2 and 5.3 install pioinit with user and group ownership of bin, which allows local users with bin or possibly printq privileges to gain root privileges by modifying pioinit.
1Ibm
1Aix
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in the atm subset in arp in devices.common.IBM.atm.rte in AIX 5.2 and 5.3 allows local users to gain root privileges.
1Ibm
1Aix
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges.
1Ibm
1Aix
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
4.7 MEDIUM· v2
rmpvc on IBM AIX 4.3 allows local users to cause a denial of service (system crash) via long port logical name (-l) argument.
1Ibm
1Lotus Sametime
Apr 23, 2026
Aug 3, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server 7.5.1 before 20070731 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a crafted Sametime meeting.
1Ibm
1Aix
Apr 23, 2026
Jul 26, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on A...Show more
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecified vectors that trigger the overflow in a gets function call. NOTE: the client is setuid root on AIX, so this issue crosses privilege boundaries.Show less
1Ibm
1Aix
Apr 23, 2026
Jul 26, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (ParseRoutine) command line argument.
1Ibm
1Aix
Apr 23, 2026
Jul 26, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences.