Show filters
66 Total Results
Displaying 21-30 of 66
Sort by:
Attacker Value
Unknown
CVE-2007-6053
Disclosure Date: November 20, 2007 (last updated October 04, 2023)
IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
0
Attacker Value
Unknown
CVE-2007-6052
Disclosure Date: November 20, 2007 (last updated October 04, 2023)
IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
0
Attacker Value
Unknown
CVE-2007-6048
Disclosure Date: November 20, 2007 (last updated October 04, 2023)
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
0
Attacker Value
Unknown
CVE-2007-6047
Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.
0
Attacker Value
Unknown
CVE-2007-4270
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.
0
Attacker Value
Unknown
CVE-2007-4271
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.
0
Attacker Value
Unknown
CVE-2007-4272
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).
0
Attacker Value
Unknown
CVE-2007-4418
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
0
Attacker Value
Unknown
CVE-2007-4273
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
0
Attacker Value
Unknown
CVE-2007-4417
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
0