Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2007-07-24 CVE-2007-3960 Remote Security vulnerability in Websphere Application Server
Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).
network
ibm
critical
9.3
2007-07-18 CVE-2007-3268 Divide By Zero vulnerability in IBM Tivoli Provisioning Manager OS Deployment 5.1.0.2
The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.
network
low complexity
ibm CWE-369
7.5
2007-07-17 CVE-2007-3831 Remote Security vulnerability in IBM products
PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
network
ibm
critical
9.3
2007-07-17 CVE-2007-3830 Cross-Site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.
network
ibm
3.5
2007-07-15 CVE-2007-3794 Buffer Overflow vulnerability in Multiple Hitachi Products GIF Image
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
network
low complexity
microsoft hitachi linux hp ibm sun
critical
10.0
2007-07-11 CVE-2007-3680 Buffer Errors vulnerability in IBM AIX 5.2.0/5.3.0
Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.
local
low complexity
ibm CWE-119
7.2
2007-07-09 CVE-2007-3626 Denial Of Service vulnerability in Hitachi TPBroker
Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.
network
low complexity
ibm hitachi sun
7.8
2007-07-03 CVE-2007-3537 Unspecified vulnerability in IBM OS 400
IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.
network
low complexity
ibm
7.8
2007-06-26 CVE-2007-3397 Information Disclosure vulnerability in IBM WebSphere Application Server Closed Connection
The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
network
low complexity
ibm
5.0
2007-06-19 CVE-2007-3265 Cross-Site Scripting vulnerability in Websphere Application Server
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm
4.3