Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2007-09-10 CVE-2007-4795 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4794 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in fcstat in devices.common.IBM.fc.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long input parameter.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4793 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4792 Buffer Errors vulnerability in IBM AIX 5.3
Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4791 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.
local
low complexity
ibm CWE-119
7.2
2007-08-15 CVE-2007-4368 SQL Injection vulnerability in IBM Rational Clearquest 7.0.0.0/7.0.0.1
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
network
low complexity
ibm CWE-89
7.5
2007-08-15 CVE-2007-4355 Local Buffer Overflow vulnerability in IBM AIX 5.3
Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm
7.2
2007-08-15 CVE-2007-4354 Buffer Overflow vulnerability in IBM AIX Fileplace Command
Buffer overflow in fileplace in bos.perf.tools in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm
7.2
2007-07-18 CVE-2007-3268 Divide By Zero vulnerability in IBM Tivoli Provisioning Manager OS Deployment 5.1.0.2
The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.
network
low complexity
ibm CWE-369
7.5
2007-07-11 CVE-2007-3680 Buffer Errors vulnerability in IBM AIX 5.2.0/5.3.0
Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.
local
low complexity
ibm CWE-119
7.2