Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2008-01-23 CVE-2008-0389 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
network
low complexity
ibm
critical
10.0
2008-01-19 CVE-2008-0369 Local Privilege Escalation vulnerability in IBM Informix Dynamic Server 10.00
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
local
ibm
6.9
2008-01-19 CVE-2008-0368 Local Privilege Escalation vulnerability in IBM Informix Dynamic Server 10.0
onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
local
low complexity
ibm
7.2
2008-01-18 CVE-2008-0354 Cross-Site Scripting vulnerability in IBM Lotus Sametime 7.5/7.5.1
Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.
network
ibm CWE-79
4.3
2008-01-12 CVE-2008-0247 Buffer Errors vulnerability in IBM Tivoli Storage Manager Express 5.3
Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.
network
low complexity
ibm CWE-119
critical
10.0
2008-01-12 CVE-2008-0243 Denial Of Service vulnerability in IBM Lotus Domino 7.0/7.0.1/7.0.2
Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.
network
low complexity
ibm
7.8
2008-01-10 CVE-2007-6680 Unspecified vulnerability in IBM AIX 6.1
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.
local
low complexity
ibm
2.1
2008-01-10 CVE-2007-6679 Remote Security vulnerability in Websphere Application Server
Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
network
low complexity
ibm
critical
10.0
2007-12-28 CVE-2007-6594 Permissions, Privileges, and Access Controls vulnerability in IBM Lotus Notes
IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.
local
ibm CWE-264
6.9
2007-12-28 CVE-2007-6593 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Lotus Notes
Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.
network
ibm CWE-119
8.8