Show filters
56 Total Results
Displaying 31-40 of 56
Sort by:
Attacker Value
Unknown
CVE-2009-1239
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
0
Attacker Value
Unknown
CVE-2009-0172
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
0
Attacker Value
Unknown
CVE-2009-0173
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
0
Attacker Value
Unknown
CVE-2008-4693
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
0
Attacker Value
Unknown
CVE-2008-4691
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-4692
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-4609
Disclosure Date: October 20, 2008 (last updated October 04, 2023)
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
0
Attacker Value
Unknown
CVE-2008-3855
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.
0
Attacker Value
Unknown
CVE-2008-3854
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
0
Attacker Value
Unknown
CVE-2008-3856
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
0