7.2

CVE-2004-2131

Exploit
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Informix Dynamic Server Version 9.40.uc1
Ibm ≫ Informix Dynamic Server Version 9.40.uc2
Ibm ≫ Informix Extended Parallel Server Version 8.40_uc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.694
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=107539878804074&w=2
http://secunia.com/advisories/10737/
http://www-1.ibm.com/support/docview.wss?uid=swg21153336
Patch
Vendor Advisory
Exploit
http://www.osvdb.org/3759
http://www.securityfocus.com/bid/9512
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/14970