Show filters
69 Total Results
Displaying 51-60 of 69
Sort by:
Attacker Value
Unknown
CVE-2009-4150
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
0
Attacker Value
Unknown
CVE-2009-3472
Disclosure Date: September 29, 2009 (last updated October 04, 2023)
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3471
Disclosure Date: September 29, 2009 (last updated October 04, 2023)
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2008-6821
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
0
Attacker Value
Unknown
CVE-2009-1906
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.
0
Attacker Value
Unknown
CVE-2008-2154
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
0
Attacker Value
Unknown
CVE-2008-6820
Disclosure Date: June 03, 2009 (last updated October 04, 2023)
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
0
Attacker Value
Unknown
CVE-2009-0172
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
0
Attacker Value
Unknown
CVE-2009-0173
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
0
Attacker Value
Unknown
CVE-2008-4693
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
0