Security
Headlines
HeadlinesLatestCVEs

Tag

#ibm

CVE-2003-0836: IBM X-Force Exchange

Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.

CVE
#buffer_overflow#ibm
CVE-2003-0658: IBM X-Force Exchange

Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.

CVE-2003-0742: IBM X-Force Exchange

SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.

CVE-2003-0769: IBM X-Force Exchange

Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.

CVE-1999-0812: IBM X-Force Exchange

Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.

CVE-2000-0220: IBM X-Force Exchange

ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.

CVE-2000-0182: IBM X-Force Exchange

iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.

CVE-2000-0143: IBM X-Force Exchange

The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.

CVE-2000-0142: IBM X-Force Exchange

The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.

CVE-2000-0145: IBM X-Force Exchange

The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.