6.5

CVE-2025-33132

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of the size of the data that is being pointed to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmDb2 High Performance Unload Load Version >= 5.1.0.0 <= 6.1.0.0
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
IbmDb2 High Performance Unload Load Version6.1.0.1 Update-
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
IbmDb2 High Performance Unload Load Version6.1.0.2 Update-
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
IbmDb2 High Performance Unload Load Version6.1.0.3 Update-
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
IbmDb2 High Performance Unload Load Version6.5.0.0
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
IbmDb2 High Performance Unload Load Version6.5.0.0 Updateif1
   IbmAix Version-
   IbmLinux On Ibm Z Version-
   LinuxLinux Kernel Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.167
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-467 Use of sizeof() on a Pointer Type

The code calls sizeof() on a pointer type, which can be an incorrect calculation if the programmer intended to determine the size of the data that is being pointed to.