Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2010-03-26 CVE-2010-1124 Remote Denial of Service vulnerability in IBM AIX 'getaddrinfo()'
bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."
network
low complexity
ibm
7.8
2010-03-23 CVE-2010-1041 Unspecified vulnerability in IBM DB2 Content Manager 8.3
Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.
network
low complexity
ibm
critical
10.0
2010-03-10 CVE-2010-0961 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX and Vios
Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2010-03-10 CVE-2010-0960 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX and Vios
Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2010-03-10 CVE-2010-0959 Cross-Site Scripting vulnerability in IBM Enovia Smarteam 5
Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.
network
ibm CWE-79
4.3
2010-03-05 CVE-2009-3032 Numeric Errors vulnerability in multiple products
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
network
low complexity
ibm symantec CWE-189
critical
10.0
2010-03-05 CVE-2010-0927 Cross-Site Scripting vulnerability in IBM Lotus Domino
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action.
network
ibm CWE-79
4.3
2010-03-05 CVE-2009-2754 Numeric Errors vulnerability in multiple products
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.
network
low complexity
ibm emc CWE-189
critical
10.0
2010-03-05 CVE-2009-2753 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Informix Dynamic Server
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.
network
low complexity
ibm CWE-119
critical
10.0
2010-03-03 CVE-2010-0922 Local Denial of Service vulnerability in IBM AIX 5.3
Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors.
network
low complexity
ibm
7.8