Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2007-05-17 CVE-2007-2736 Remote File Include vulnerability in Achievo 1.1.0
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
network
low complexity
apple hp ibm linux microsoft santa-cruz-operation sun windriver achievo
critical
10.0
2007-05-10 CVE-2007-2582 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."
network
low complexity
ibm CWE-119
critical
10.0
2007-04-30 CVE-2006-7198 Remote Security vulnerability in Websphere Application Server
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
network
low complexity
ibm
critical
10.0
2007-04-24 CVE-2007-2191 HTML Injection vulnerability in Freepbx 2.2.1/2.2Rc1
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
6.8
2007-04-22 CVE-2007-2137 Heap Buffer Overflow vulnerability in IBM Tivoli Monitoring Express 6.1.0
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.
network
low complexity
ibm
critical
10.0
2007-04-11 CVE-2007-1945 Unspecified vulnerability in IBM Websphere Application Server
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
network
low complexity
hp ibm linux microsoft sun
7.5
2007-04-11 CVE-2007-1944 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Websphere Application Server
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
network
low complexity
ibm CWE-119
5.0
2007-04-11 CVE-2007-1941 HTML Injection vulnerability in IBM Lotus Domino Web Access Active Content Filter
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.
network
ibm
4.3
2007-04-11 CVE-2007-1940 Unspecified vulnerability in IBM Tivoli Business Service Manager 4.1
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.
local
low complexity
ibm
4.9
2007-04-04 CVE-2007-1868 Stack Buffer Overflow vulnerability in IBM Tivoli Provisioning Manager OS Deployment 5.1.0.116
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
network
low complexity
ibm
critical
10.0