Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown

CVE-2008-3857

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
0
Attacker Value
Unknown

CVE-2008-3853

Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
0
Attacker Value
Unknown

CVE-2007-5664

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
0
Attacker Value
Unknown

CVE-2007-5758

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
0
Attacker Value
Unknown

CVE-2007-5757

Disclosure Date: February 13, 2008 (last updated October 04, 2023)
Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
0
Attacker Value
Unknown

CVE-2007-6051

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
0
Attacker Value
Unknown

CVE-2007-6046

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
0
Attacker Value
Unknown

CVE-2007-6045

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-6050

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."
0
Attacker Value
Unknown

CVE-2007-6049

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
0