Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown
CVE-2017-1520
Disclosure Date: September 12, 2017 (last updated November 26, 2024)
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
0
Attacker Value
Unknown
CVE-2016-5995
Disclosure Date: October 01, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
0
Attacker Value
Unknown
CVE-2016-0211
Disclosure Date: April 28, 2016 (last updated November 25, 2024)
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.
0
Attacker Value
Unknown
CVE-2014-3095
Disclosure Date: September 04, 2014 (last updated October 05, 2023)
The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.
0
Attacker Value
Unknown
CVE-2014-3094
Disclosure Date: September 04, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
0
Attacker Value
Unknown
CVE-2013-6744
Disclosure Date: May 30, 2014 (last updated October 05, 2023)
The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.
0
Attacker Value
Unknown
CVE-2014-0907
Disclosure Date: May 30, 2014 (last updated October 05, 2023)
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
0
Attacker Value
Unknown
CVE-2013-6717
Disclosure Date: December 19, 2013 (last updated October 05, 2023)
The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4826
Disclosure Date: October 20, 2012 (last updated October 05, 2023)
Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.
0
Attacker Value
Unknown
CVE-2012-0713
Disclosure Date: August 24, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.
0