Перейти к содержимому
Noroxi

Записи IBM

8 833 опубликованных записей вендора ibm.

Профиль для исследователя

Попали в KEV
10 · 0,1 %
С эксплойтом
60 · 0,7 %
Pre-auth RCE
456
С записью об исправлении
1,9 %
Медиана: публикация → KEV
1193 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

8 833 записей
  • CVE-2014-6271
    99Срочно

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2017-5638
    99Срочно

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · struts10 мар. 2017 г.

  • CVE-2022-47986
    99Срочно

    IBM Aspera Faspex code execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ibm · aspera faspex17 февр. 2023 г.

  • CVE-2014-7169
    99Срочно

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2015-7450
    98Срочно

    Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    ibm · sterling b2b integrator2 янв. 2016 г.

  • CVE-2019-4716
    95Срочно

    IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %

    ibm · planning analytics18 дек. 2019 г.

  • CVE-2020-4427
    90Срочно

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %

    ibm · data risk manager7 мая 2020 г.

  • CVE-2020-4428
    85Срочно

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 62 %

    ibm · data risk manager7 мая 2020 г.

  • CVE-2001-0797
    68На этой неделе

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe

    КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %

    sgi · irix12 дек. 2001 г.

  • CVE-2015-0235
    68На этой неделе

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %

    gnu · glibc28 янв. 2015 г.

  • CVE-2010-0425
    68На этой неделе

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, w

    КритическаяCVSS 10,0Готовый эксплойтEPSS 94 %

    apache · http server5 мар. 2010 г.

  • CVE-2020-4430
    68На этой неделе

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.

    СредняяCVSS 4,3KEVГотовый эксплойтEPSS 69 %

    ibm · data risk manager7 мая 2020 г.

  • CVE-2019-4279
    63На этой неделе

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted

    КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %

    ibm · websphere application server17 мая 2019 г.

  • CVE-2007-4880
    63На этой неделе

    Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2

    КритическаяCVSS 10,0Готовый эксплойтEPSS 76 %

    ibm · tivoli storage manager client27 сент. 2007 г.

  • CVE-2024-22319
    62На этой неделе

    IBM Operational Decision Manager JDNI injection

    КритическаяCVSS 9,8Proof of conceptEPSS 76 %

    ibm · operational decision manager1 февр. 2024 г.

  • CVE-2017-1092
    62На этой неделе

    IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows serv

    КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %

    ibm · informix open admin tool22 мая 2017 г.

  • CVE-2020-4429
    61На этой неделе

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %

    ibm · data risk manager7 мая 2020 г.

  • CVE-2008-4828
    61На этой неделе

    Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 thr

    КритическаяCVSS 10,0Готовый эксплойтEPSS 71 %

    ibm · tivoli storage manager client5 мая 2009 г.

  • CVE-2020-4211
    60На этой неделе

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.

    КритическаяCVSS 9,8Эксплойта нетEPSS 71 %

    ibm · spectrum protect24 февр. 2020 г.

  • CVE-2003-0694
    60На этой неделе

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using

    КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %

    sendmail · advanced message server6 окт. 2003 г.

  • CVE-2008-2240
    59В плане

    Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to

    КритическаяCVSS 10,0Готовый эксплойтEPSS 65 %

    ibm · lotus domino22 мая 2008 г.

  • CVE-2009-3699
    59В плане

    Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1

    КритическаяCVSS 10,0Готовый эксплойтEPSS 62 %

    ibm · vios15 окт. 2009 г.

  • CVE-2007-1675
    58В плане

    Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.

    КритическаяCVSS 10,0Proof of conceptEPSS 61 %

    ibm · lotus domino28 мар. 2007 г.

  • CVE-2007-1868
    58В плане

    The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-da

    КритическаяCVSS 10,0Готовый эксплойтEPSS 59 %

    ibm · tivoli provisioning manager os deployment4 апр. 2007 г.

  • CVE-2020-4280
    57В плане

    IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of

    ВысокаяCVSS 8,8Эксплойта нетEPSS 73 %

    ibm · qradar security information and event manager8 окт. 2020 г.