Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2001-07-02 CVE-2001-0390 Denial of Service vulnerability in IBM products
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
network
low complexity
ibm
5.0
2001-07-02 CVE-2001-0389 Unspecified vulnerability in IBM Net.Commerce and Websphere Application Server
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
network
low complexity
ibm
5.0
2001-06-27 CVE-2001-0487 Denial-Of-Service vulnerability in Aix Snmp
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
network
low complexity
ibm
5.0
2001-06-27 CVE-2001-0472 Denial-Of-Service vulnerability in IBM High Availability Cluster Multiprocessing 1.0
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
network
low complexity
ibm
5.0
2001-06-18 CVE-2001-0446 Remote Security vulnerability in IBM Websphere Commerce Suite 4.0.1
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
network
low complexity
ibm
5.0
2001-06-02 CVE-2001-0312 Remote Security vulnerability in Websphere Plugin
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
network
low complexity
ibm
5.0
2001-03-13 CVE-2001-0122 Unspecified vulnerability in IBM Http Server and Websphere Application Server
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
network
low complexity
ibm
5.0
2001-03-12 CVE-1999-0729 Unspecified vulnerability in IBM Lotus Domino Server 4.6
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
network
low complexity
ibm
5.0
2001-03-12 CVE-1999-0718 Privilege Escalation vulnerability in IBM Gina 1.0
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.
local
high complexity
ibm
6.2
2001-01-09 CVE-2000-1119 Unspecified vulnerability in IBM AIX
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
local
low complexity
ibm
4.6