Show filters
124 Total Results
Displaying 41-50 of 124
Sort by:
Attacker Value
Unknown

CVE-2018-1781

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.
0
Attacker Value
Unknown

CVE-2018-1834

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
0
Attacker Value
Unknown

CVE-2018-1802

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.
0
Attacker Value
Unknown

CVE-2018-1780

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.
0
Attacker Value
Unknown

CVE-2018-1711

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.
0
Attacker Value
Unknown

CVE-2018-1685

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
0
Attacker Value
Unknown

CVE-2018-1487

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.
0
Attacker Value
Unknown

CVE-2018-1458

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
0
Attacker Value
Unknown

CVE-2018-1566

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.
0
Attacker Value
Unknown

CVE-2018-1565

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.
0