IBM Global Services

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 27 - 41 of 101
First | Prev. | 1 2 3 4 5 6 | Next | Last 

IZ01272: Potential security exposure in MQ client channels

A problem has been discovered which can enable an application to connect into a queue manager via a SVRCONN (MQ client) channel regardless of whether it is secured with a security exit or mcauser.

29 february, 2008

AIX libc inet_network buffer overflow

There is an off-by-one error in the AIX libc implementation of the inet_network function.

28 february, 2008

AIX X server multiple vulnerabilities

The successful exploitation of these vulnerabilities allows a non-privileged user to execute code with root privileges.

28 february, 2008

IBM Pegasus CIM Server for Director on AIX vulnerabilities

Two vulnerabilities have been addressed in the IBM Pegasus CIM Server for Director.

22 february, 2008

Possible Java plug-in vulnerability in Lotus Notes

David Gloede contacted IBM® Lotus® to report that the Notes® client was affected by a Java plug-in vulnerability originally documented in an advisory by Jouko Pynnonen.

20 february, 2008

Java applet signatures and the Execution Control List

David Gloede contacted IBM® Lotus® to report a potential security issue with the Execution Control List (ECL) and Notes® signatures on Java applets.

20 february, 2008

AIX swap commands buffer overflow

A local attacker may execute arbitrary code with root privileges because the commands are setuid root.

24 january, 2008

AIX incorrect file permissions Linux WebSM remote client

The successful exploitation of this vulnerability allows a non-privileged local user alter the behavior of the WebSM Remote Client on the Linux system.

24 january, 2008

AIX Logical Volume Manager buffer overflow

A local attacker may execute arbitrary code with root privileges because the commands are setuid root.

24 january, 2008

AIX utape buffer overflow

A local attacker may execute arbitrary code with root privileges because the commands are setuid root.

24 january, 2008

AIX uspchrp buffer overflow

A local attacker may execute arbitrary code with root privileges because the commands are setuid root.

24 january, 2008

AIX ps information leak

A local attacker may access sensitive information for arbitrary processes.

24 january, 2008

AIX pioout buffer overflow

A local attacker may execute arbitrary code with root privileges because the commands are setuid root.

24 january, 2008

Tivoli Provisioning Manager for OS Deployment 5.1.0-TIV-TPMOSD-IF0003

Tivoli® Provisioning Manager for OS Deployment, Interim Fix 3, Version 5.1.0.3, including enhancements added since Tivoli Provisioning Manager for OS Deployment, Fix Pack, Version

22 january, 2008

IBM Tivoli Business Service Manager V4.1.1 Interim Fix 1(4.1.1.0-TIV-BSM-IF0001)

This Interim Fix addresses problems reported in IBM Tivoli Business Service Manager 4.1.1

22 january, 2008

Óâåäîìëåíèÿ 27 - 41 of 101
First | Prev. | 1 2 3 4 5 6 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution