← Back

Ibm

ibm

8,704 CVEs • 1,613 products

Products (1,613)

Click to collapse
Toggle
Aix
aix
Db2
db2
Vios
vios
I
i
Websphere Mq
websphere_mq
Lotus Domino
lotus_domino
Api Connect
api_connect
Lotus Notes
lotus_notes
Concert
concert
Aspera Faspex
aspera_faspex
Mq Appliance
mq_appliance
Mq
mq
Sametime
sametime
Cics Tx
cics_tx
Connections
connections
Java
java
Domino
domino

CVEs (8,704)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Informix Dynamic Server
Apr 23, 2026
Oct 5, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
IBM Informix Dynamic Server 10.UC3RC1 Trial for Linux and possibly other versions creates /tmp/installserver.txt with insecure permissions, which allows local users to append data to arbitrary files via a symlink attack.
1Ibm
1Client Security Password Manager
Apr 23, 2026
Oct 5, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML pa...Show more
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.Show less
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.
1Ibm
1Aix
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.
1Ibm
1Aix
Apr 16, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
1Ibm
1Inventory Scout
Apr 16, 2026
Sep 27, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.
1Ibm
1Lotus Domino Web Access
Apr 16, 2026
Sep 13, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the Ltp...Show more
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.Show less
1Ibm
1Director
Apr 16, 2026
Sep 11, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.
1Ibm
1Director
Apr 16, 2026
Sep 11, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packe...Show more
Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.Show less
1Ibm
1Director
Apr 16, 2026
Sep 11, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.
1Ibm
1Aix
Apr 16, 2026
Sep 1, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
1Ibm
1Aix
Apr 16, 2026
Aug 28, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg pro...Show more
Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program.Show less
1Ibm
1Db2
Apr 16, 2026
Aug 21, 2006
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process,...Show more
IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.Show less
1Ibm
1Aix
Apr 16, 2026
Aug 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.