Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2010-1321

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
0
Attacker Value
Unknown

CVE-2009-4150

Disclosure Date: December 02, 2009 (last updated October 04, 2023)
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
0
Attacker Value
Unknown

CVE-2009-0172

Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
0
Attacker Value
Unknown

CVE-2009-0173

Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
0
Attacker Value
Unknown

CVE-2008-3855

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.
0
Attacker Value
Unknown

CVE-2008-3854

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
0
Attacker Value
Unknown

CVE-2008-3856

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2008-3852

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-3858

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
0
Attacker Value
Unknown

CVE-2008-3857

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
0