Vulnerabilities > IBM > High

DATE CVE VULNERABILITY TITLE RISK
1999-03-01 CVE-1999-0429 Unspecified vulnerability in IBM Lotus Notes 4.5
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
network
low complexity
ibm
7.5
1998-11-16 CVE-1999-0057 Vacation program allows command execution by remote users through a sendmail command.
network
low complexity
eric-allman freebsd hp ibm sun
7.5
1998-11-01 CVE-1999-0118 Unspecified vulnerability in IBM AIX
AIX infod allows local users to gain root access through an X display.
local
low complexity
ibm
7.2
1998-10-02 CVE-1999-1403 Multiple vulnerability in IBM Tivoli OPC Tracker Agent 1.0X/2.0X/3.0X
IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.
local
low complexity
ibm
7.2
1998-07-06 CVE-1999-1574 Unspecified vulnerability in IBM AIX 4.3.0
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
network
low complexity
ibm
7.5
1998-05-14 CVE-1999-0055 Buffer overflows in Sun libnsl allow root access.
local
low complexity
ibm sun
7.2
1998-01-21 CVE-1999-1487 Unspecified vulnerability in IBM AIX
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
local
low complexity
ibm
7.2
1998-01-21 CVE-1999-0014 Unauthorized privileged access or denial of service via dtappgather program in CDE.
local
low complexity
cde hp ibm
7.2
1998-01-01 CVE-1999-0284 Classic Buffer Overflow vulnerability in multiple products
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
network
low complexity
ibm microsoft CWE-120
7.5
1997-12-10 CVE-1999-0017 FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. 7.5