Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2002-10-04 CVE-2002-1041 Remote Security vulnerability in IBM AIX DCE
Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.
network
low complexity
ibm
5.0
2002-10-04 CVE-2002-1040 Remote Security vulnerability in IBM AIX Websecure
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
network
low complexity
ibm
5.0
2002-07-31 CVE-2002-1450 Denial-Of-Service vulnerability in IBM Universe
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.
network
low complexity
ibm
5.0
2002-04-01 CVE-2002-1620 Remote Security vulnerability in IBM AIX Parallel Systems Support Programs 3.1.1/3.2/3.4
Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection.
network
low complexity
ibm
5.0
2002-03-08 CVE-2002-1619 Denial-Of-Service vulnerability in AIX
Buffer overflow in the FC client for IBM AIX 4.3.x allows remote attackers to cause a denial of service (crash and core dump).
network
low complexity
ibm
5.0
2001-12-31 CVE-2001-1567 Remote Authentication Bypass vulnerability in IBM Lotus Domino and Lotus Domino Server
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
network
low complexity
ibm
5.0
2001-12-31 CVE-2001-1554 Denial-Of-Service vulnerability in IBM AIX 430
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.
network
low complexity
ibm
5.0
2001-12-13 CVE-2001-1189 Unspecified vulnerability in IBM Websphere Application Server
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
local
low complexity
ibm
4.6
2001-12-11 CVE-2001-1191 Denial Of Service vulnerability in IBM Tivoli Secureway Policy Director 3.8
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
network
low complexity
ibm
5.0
2001-12-06 CVE-2001-0856 Unspecified vulnerability in IBM 4758
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.
local
low complexity
ibm
4.6