Ibm

Db2

292 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 20.79%
  • Published 10.05.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an ...

  • EPSS 0.06%
  • Published 02.03.2007 22:19:00
  • Last modified 09.04.2025 00:30:58

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.

  • EPSS 0.08%
  • Published 23.02.2007 22:28:00
  • Last modified 09.04.2025 00:30:58

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

  • EPSS 0.08%
  • Published 23.02.2007 22:28:00
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.

  • EPSS 0.05%
  • Published 21.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.

  • EPSS 1.26%
  • Published 21.08.2006 20:04:00
  • Last modified 03.04.2025 01:03:51

IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA...

  • EPSS 0.16%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

  • EPSS 2.2%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which cause...

  • EPSS 0.32%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile ...

  • EPSS 0.06%
  • Published 29.06.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.