Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
2007-02-23 CVE-2007-1087 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
local
low complexity
ibm CWE-119
7.2
2007-02-23 CVE-2007-1086 Local Privilege Escalation vulnerability in IBM DB2 Universal Database
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
local
low complexity
hp ibm linux microsoft sun
7.2
2007-02-23 CVE-2006-7034 SQL-Injection vulnerability in Super Link Exchange Script Super Link Exchange Script 1.0
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
7.5
2007-02-21 CVE-2007-1043 Authentication Bypass vulnerability in Ezboo Webstats 3.0.3
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
7.5
2007-02-16 CVE-2007-0978 Local Security vulnerability in IBM AIX 5.3
Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.
local
low complexity
ibm
7.2
2007-02-16 CVE-2007-0977 Remote Security vulnerability in Lotus Domino 5.0/6.0
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
network
ibm
7.1
2007-01-31 CVE-2007-0618 Authentication Bypass vulnerability in IBM AIX 5.3.0
Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
network
low complexity
ibm
7.5
2006-12-14 CVE-2006-6537 Security Bypass vulnerability in Websphere Host On-Demand
IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.
network
low complexity
ibm
7.5
2006-12-06 CVE-2006-6309 Denial-Of-Service vulnerability in Tivoli Storage Manager Express
Multiple array index errors in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to read arbitrary memory locations and cause a denial of service (crash) via a large index value in unspecified messages, a different issue than CVE-2006-5855.
network
low complexity
ibm
7.5
2006-11-08 CVE-2006-5818 TuneKrnl Local Privilege Escalation vulnerability in IBM Lotus Domino
Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.
local
low complexity
ibm
7.2