Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2007-11-05 CVE-2007-4621 Buffer Errors vulnerability in IBM AIX 5.2
Buffer overflow in crontab in IBM AIX 5.2 allows local users to gain privileges via long command line arguments.
local
low complexity
ibm CWE-119
7.2
2007-11-05 CVE-2007-4513 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Multiple stack-based buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via a long argument to the (1) "-p" option to lqueryvg or (2) the "-V" option to lquerypv.
local
low complexity
ibm CWE-119
7.2
2007-11-05 CVE-2007-4217 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the '$' command.
local
low complexity
ibm CWE-119
7.2
2007-11-03 CVE-2007-5799 Cross-Site Request Forgery (CSRF) vulnerability in IBM Websphere Application Server
Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
network
ibm CWE-352
4.3
2007-11-03 CVE-2007-5798 Cross-Site Scripting vulnerability in IBM Websphere Application Server
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
network
ibm CWE-79
4.3
2007-10-30 CVE-2007-4348 Cross-Site Scripting vulnerability in IBM Tivoli Storage Manager Client
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
network
ibm CWE-79
4.3
2007-10-29 CVE-2007-4222 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Lotus Notes
Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.
network
ibm CWE-119
critical
9.3
2007-10-29 CVE-2007-5701 Information Exposure vulnerability in IBM Lotus Domino
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel.
local
low complexity
ibm CWE-200
2.1
2007-10-29 CVE-2007-5700 Information Disclosure vulnerability and Buffer Overflow vulnerability in IBM Lotus Domino
The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenticated users to gain privileges and obtain sensitive information.
network
ibm
6.3
2007-10-29 CVE-2007-5544 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Lotus Notes
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
local
low complexity
ibm CWE-732
7.8