Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2008-05-22 CVE-2008-2410 Cross-Site Scripting vulnerability in IBM Lotus Domino web Server
Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2008-05-22 CVE-2008-2240 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Lotus Domino
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.
network
low complexity
ibm CWE-119
critical
10.0
2008-05-14 CVE-2008-2221 Unspecified vulnerability in IBM Websphere Application Server 5.0.2
Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.
network
low complexity
ibm
critical
10.0
2008-05-13 CVE-2008-2163 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.1
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
network
ibm microsoft CWE-79
4.3
2008-05-09 CVE-2008-2122 Missing Release of Resource after Effective Lifetime vulnerability in IBM Rational Build Forge 7.0.2
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.
network
low complexity
ibm CWE-772
7.5
2008-04-28 CVE-2008-1998 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 8.0/9.1/9.5
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
8.5
2008-04-27 CVE-2008-1966 Buffer Errors vulnerability in IBM DB2 8.0/9.1/9.5
Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.
network
low complexity
ibm CWE-119
4.0
2008-04-25 CVE-2008-1965 Code Injection vulnerability in IBM Lotus Expeditor Client and Lotus Symphany
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.
network
ibm CWE-94
critical
9.3
2008-04-16 CVE-2007-5758 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database 8/9.1/9.5
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
local
ibm CWE-119
6.9
2008-04-16 CVE-2007-5664 Link Following vulnerability in IBM DB2 Universal Database 8/9.1/9.5
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
local
ibm CWE-59
6.9