← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Aix
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
1Ibm
1Aix
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
1Ibm
1Aix
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as...Show more
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.Show less
1Ibm
1Lotus Notes
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
1Ibm
1Aix
Apr 16, 2026
Dec 21, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.
1Ibm
1Websphere Application Server
Apr 16, 2026
Dec 13, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
5Hp
IbmSco+2 more
6Aix
Hp UxIrix+3 more
Apr 16, 2026
Dec 12, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
1Ibm
1Tivoli Secureway Policy Director
Apr 16, 2026
Dec 11, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
1Ibm
14758
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES expor...Show more
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/...Show more
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.Show less
1Ibm
1Aix
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
1Ibm
1Informix Web Datablade
Apr 16, 2026
Nov 22, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.
1Ibm
1Aix
Apr 16, 2026
Oct 9, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.
1Ibm
1Aix
Apr 16, 2026
Oct 9, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.
1Ibm
2Aix
Hacmp
Apr 16, 2026
Sep 24, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.
2Hp
Ibm
2Openview Network Node Manager
Tivoli Netview
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.
1Ibm
2Websphere Application Server
Websphere Commerce Suite
Apr 16, 2026
Sep 19, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
1Ibm
1Lotus Domino
Apr 16, 2026
Sep 19, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information...Show more
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.Show less
1Ibm
1Aix
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
1Ibm
1Http Server Ssl Module Common
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root...Show more
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.Show less