← Back

Ibm

ibm

8,250 CVEs • 1,572 products

Products (1,572)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
I
i
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Aspera Faspex
aspera_faspex
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino
Doors Next
doors_next

CVEs (8,250)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
9Debian
FreebsdIbm+6 more
11Aix
Debian LinuxFreebsd+8 more
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.Show less
1Ibm
1Aix
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.
1Ibm
1Aix
Apr 16, 2026
Aug 2, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the progr...Show more
lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.Show less
1Ibm
1Tivoli Secureway Policy Director
Apr 16, 2026
Jul 23, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.
1Ibm
1Lotus Notes
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.
1Ibm
1Alphaworks Tftp Server
Apr 16, 2026
Jul 20, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.
1Ibm
1Lotus Domino R5
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv...Show more
Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.Show less
1Ibm
1Lotus Domino R5
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Ibm
1Lotus Domino R5
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Ibm
1Secureway Directory
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suit...Show more
IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.Show less
1Ibm
1Secureway Directory
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Ibm
1Db2 Universal Database
Apr 16, 2026
Jul 11, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
1Ibm
1Visualage For Java
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.
1Ibm
3Net.commerce
Net.commerce Hosting ServerWebsphere Application Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
1Ibm
2Net.commerce
Websphere Application Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
1Ibm
1Aix Snmp
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
1Ibm
1High Availability Cluster Multiprocessing
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
1Ibm
1Aix
Apr 16, 2026
Jun 19, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
1Ibm
1Websphere Commerce Suite
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
1Ibm
1Aix
Apr 16, 2026
Jun 11, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.