Total
67 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-1372 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure. | |||||
CVE-2004-0795 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe. | |||||
CVE-2003-1052 | 1 Ibm | 2 Db2, Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs. | |||||
CVE-2003-1049 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 4.6 MEDIUM | N/A |
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files. | |||||
CVE-2003-0898 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 4.6 MEDIUM | N/A |
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2. | |||||
CVE-2003-0837 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.5 HIGH | N/A |
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command. | |||||
CVE-2003-0836 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.5 HIGH | N/A |
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command. | |||||
CVE-2003-0827 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 5.0 MEDIUM | N/A |
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523. | |||||
CVE-2003-0759 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument. | |||||
CVE-2003-0758 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument. | |||||
CVE-2002-1583 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.2 HIGH | N/A |
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument. | |||||
CVE-2001-1143 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 5.0 MEDIUM | N/A |
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. | |||||
CVE-2001-0052 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 2.1 LOW | N/A |
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. | |||||
CVE-2001-0051 | 1 Ibm | 1 Db2 Universal Database | 2024-11-20 | 7.5 HIGH | N/A |
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database. | |||||
CVE-2010-3739 | 1 Ibm | 1 Db2 Universal Database | 2024-02-28 | 6.4 MEDIUM | N/A |
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery. | |||||
CVE-2008-3858 | 1 Ibm | 1 Db2 Universal Database | 2024-02-28 | 4.3 MEDIUM | N/A |
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request. | |||||
CVE-2009-4150 | 1 Ibm | 2 Db2, Db2 Universal Database | 2024-02-28 | 4.6 MEDIUM | N/A |
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors. | |||||
CVE-2009-0172 | 1 Ibm | 1 Db2 Universal Database | 2024-02-28 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream. | |||||
CVE-2008-3856 | 1 Ibm | 1 Db2 Universal Database | 2024-02-28 | 7.5 HIGH | N/A |
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors. | |||||
CVE-2008-3855 | 1 Ibm | 1 Db2 Universal Database | 2024-02-28 | 4.6 MEDIUM | N/A |
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664. |