Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2009-4150
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
0
Attacker Value
Unknown
CVE-2008-3960
Disclosure Date: September 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
0
Attacker Value
Unknown
CVE-2008-3856
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2007-5664
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
0
Attacker Value
Unknown
CVE-2007-5758
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
0
Attacker Value
Unknown
CVE-2007-4423
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
0
Attacker Value
Unknown
CVE-2007-1086
Disclosure Date: February 23, 2007 (last updated October 04, 2023)
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
0
Attacker Value
Unknown
CVE-2006-6638
Disclosure Date: December 19, 2006 (last updated October 04, 2023)
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
0
Attacker Value
Unknown
CVE-2006-3066
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
0
Attacker Value
Unknown
CVE-2006-3068
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
0