Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Db2 Universal Database
Total 67 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1372 1 Ibm 1 Db2 Universal Database 2024-11-20 7.2 HIGH N/A
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
CVE-2004-0795 1 Ibm 1 Db2 Universal Database 2024-11-20 7.2 HIGH N/A
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
CVE-2003-1052 1 Ibm 2 Db2, Db2 Universal Database 2024-11-20 7.2 HIGH N/A
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
CVE-2003-1049 1 Ibm 1 Db2 Universal Database 2024-11-20 4.6 MEDIUM N/A
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.
CVE-2003-0898 1 Ibm 1 Db2 Universal Database 2024-11-20 4.6 MEDIUM N/A
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
CVE-2003-0837 1 Ibm 1 Db2 Universal Database 2024-11-20 7.5 HIGH N/A
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.
CVE-2003-0836 1 Ibm 1 Db2 Universal Database 2024-11-20 7.5 HIGH N/A
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.
CVE-2003-0827 1 Ibm 1 Db2 Universal Database 2024-11-20 5.0 MEDIUM N/A
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
CVE-2003-0759 1 Ibm 1 Db2 Universal Database 2024-11-20 7.2 HIGH N/A
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.
CVE-2003-0758 1 Ibm 1 Db2 Universal Database 2024-11-20 7.2 HIGH N/A
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.
CVE-2002-1583 1 Ibm 1 Db2 Universal Database 2024-11-20 7.2 HIGH N/A
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.
CVE-2001-1143 1 Ibm 1 Db2 Universal Database 2024-11-20 5.0 MEDIUM N/A
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
CVE-2001-0052 1 Ibm 1 Db2 Universal Database 2024-11-20 2.1 LOW N/A
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
CVE-2001-0051 1 Ibm 1 Db2 Universal Database 2024-11-20 7.5 HIGH N/A
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
CVE-2010-3739 1 Ibm 1 Db2 Universal Database 2024-02-28 6.4 MEDIUM N/A
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
CVE-2008-3858 1 Ibm 1 Db2 Universal Database 2024-02-28 4.3 MEDIUM N/A
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
CVE-2009-4150 1 Ibm 2 Db2, Db2 Universal Database 2024-02-28 4.6 MEDIUM N/A
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
CVE-2009-0172 1 Ibm 1 Db2 Universal Database 2024-02-28 5.0 MEDIUM N/A
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
CVE-2008-3856 1 Ibm 1 Db2 Universal Database 2024-02-28 7.5 HIGH N/A
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
CVE-2008-3855 1 Ibm 1 Db2 Universal Database 2024-02-28 4.6 MEDIUM N/A
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.