Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2001-06-27 CVE-2001-0487 Denial-Of-Service vulnerability in Aix Snmp
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
network
low complexity
ibm
5.0
2001-06-27 CVE-2001-0472 Denial-Of-Service vulnerability in IBM High Availability Cluster Multiprocessing 1.0
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
network
low complexity
ibm
5.0
2001-06-18 CVE-2001-0446 Remote Security vulnerability in IBM Websphere Commerce Suite 4.0.1
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
network
low complexity
ibm
5.0
2001-06-02 CVE-2001-0312 Remote Security vulnerability in Websphere Plugin
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
network
low complexity
ibm
5.0
2001-03-13 CVE-2001-0122 Unspecified vulnerability in IBM Http Server and Websphere Application Server
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
network
low complexity
ibm
5.0
2001-03-12 CVE-1999-0729 Unspecified vulnerability in IBM Lotus Domino Server 4.6
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
network
low complexity
ibm
5.0
2001-03-12 CVE-1999-0718 Privilege Escalation vulnerability in IBM Gina 1.0
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.
local
high complexity
ibm
6.2
2001-01-09 CVE-2000-1119 Unspecified vulnerability in IBM AIX
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
local
low complexity
ibm
4.6
2001-01-09 CVE-2000-1110 Path Disclosure vulnerability in IBM Net.Data 7.0
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
network
low complexity
ibm
5.0
2000-12-11 CVE-2000-1038 Unspecified vulnerability in IBM As400 Firewall R440
The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.
network
low complexity
ibm
5.0