Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2010-3739
Disclosure Date: October 05, 2010 (last updated October 04, 2023)
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
0
Attacker Value
Unknown
CVE-2009-4150
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
0
Attacker Value
Unknown
CVE-2009-0172
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
0
Attacker Value
Unknown
CVE-2009-0173
Disclosure Date: January 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
0
Attacker Value
Unknown
CVE-2008-3854
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.
0
Attacker Value
Unknown
CVE-2008-3852
Disclosure Date: August 28, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-5664
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
0
Attacker Value
Unknown
CVE-2007-5758
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
0