4

CVE-2008-1966

Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmDb2 Version8.0
IbmDb2 Version8.0 Updatefp1
IbmDb2 Version8.0 Updatefp10
IbmDb2 Version8.0 Updatefp11
IbmDb2 Version8.0 Updatefp12
IbmDb2 Version8.0 Updatefp13
IbmDb2 Version8.0 Updatefp14
IbmDb2 Version8.0 Updatefp15
IbmDb2 Version8.0 Updatefp2
IbmDb2 Version8.0 Updatefp3
IbmDb2 Version8.0 Updatefp4
IbmDb2 Version8.0 Updatefp4a
IbmDb2 Version8.0 Updatefp5
IbmDb2 Version8.0 Updatefp6
IbmDb2 Version8.0 Updatefp6a
IbmDb2 Version8.0 Updatefp6b
IbmDb2 Version8.0 Updatefp6c
IbmDb2 Version8.0 Updatefp7
IbmDb2 Version8.0 Updatefp7a
IbmDb2 Version8.0 Updatefp7b
IbmDb2 Version8.0 Updatefp8
IbmDb2 Version8.0 Updatefp8a
IbmDb2 Version8.0 Updatefp9
IbmDb2 Version8.0 Updatefp9a
IbmDb2 Version9.5
IbmDb2 Version9.1
IbmDb2 Version9.1 Updatefp1
IbmDb2 Version9.1 Updatefp2
IbmDb2 Version9.1 Updatefp2a
IbmDb2 Version9.1 Updatefp3
IbmDb2 Version9.1 Updatefp3a
IbmDb2 Version9.1 Updatefp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.17% 0.836
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.