← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Aix
Apr 16, 2026
Dec 15, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
1Ibm
1Aix
Apr 16, 2026
Dec 15, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
1Ibm
1Aix
Apr 16, 2026
Dec 15, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
1Ibm
1Aix
Apr 16, 2026
Dec 8, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
1Ibm
1Websphere Application Server
Apr 16, 2026
Nov 22, 2005
N/A· v4
N/A· v3
7.8 HIGH· v2
Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
1Ibm
1Aix
Apr 16, 2026
Nov 22, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.
1Ibm
1Db2 Universal Database
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
1Ibm
1Informix Dynamic Database Server
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.
1Ibm
1Db2 Content Manager
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.
1Ibm
1Db2 Content Manager
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT S...Show more
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."Show less
1Ibm
1Tivoli Directory Server
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
5.8 MEDIUM· v2
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
1Ibm
1Aix
Apr 16, 2026
Nov 5, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.
1Ibm
1Websphere Application Server
Apr 16, 2026
Nov 4, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an applicat...Show more
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.Show less
1Ibm
1Aix
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
1Ibm
1Aix
Apr 16, 2026
Oct 23, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
1Ibm
1Aix
Apr 16, 2026
Sep 30, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.
1Ibm
2Lotus Domino
Lotus Domino Enterprise Server
Apr 16, 2026
Sep 21, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
1Ibm
1Rational Clearquest
Apr 16, 2026
Sep 20, 2005
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).
1Ibm
1Lotus Notes
Apr 16, 2026
Aug 26, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration...Show more
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.Show less
1Ibm
1Lotus Domino
Apr 16, 2026
Aug 3, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive informati...Show more
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.Show less