Show filters
69 Total Results
Displaying 31-40 of 69
Sort by:
Attacker Value
Unknown

CVE-2010-3732

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
0
Attacker Value
Unknown

CVE-2010-3733

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
0
Attacker Value
Unknown

CVE-2010-3738

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
0
Attacker Value
Unknown

CVE-2010-3194

Disclosure Date: August 31, 2010 (last updated October 04, 2023)
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
0
Attacker Value
Unknown

CVE-2010-3195

Disclosure Date: August 31, 2010 (last updated October 04, 2023)
Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."
0
Attacker Value
Unknown

CVE-2010-3193

Disclosure Date: August 31, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2010-0462

Disclosure Date: January 28, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
0
Attacker Value
Unknown

CVE-2009-4438

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4439

Disclosure Date: December 28, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query.
0
Attacker Value
Unknown

CVE-2009-4328

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.
0