Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown

CVE-2006-3066

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
0
Attacker Value
Unknown

CVE-2006-3068

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
0
Attacker Value
Unknown

CVE-2006-3067

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
0
Attacker Value
Unknown

CVE-2005-4869

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
0
Attacker Value
Unknown

CVE-2005-4868

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
Attacker Value
Unknown

CVE-2005-4870

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.
0
Attacker Value
Unknown

CVE-2005-4871

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.
0
Attacker Value
Unknown

CVE-2005-4739

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.
0
Attacker Value
Unknown

CVE-2005-4738

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.
0
Attacker Value
Unknown

CVE-2005-4865

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
0