CVE-2009-4150
- EPSS 0.11%
- Veröffentlicht 02.12.2009 11:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
CVE-2009-3471
- EPSS 0.85%
- Veröffentlicht 29.09.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
CVE-2009-3472
- EPSS 0.57%
- Veröffentlicht 29.09.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
- EPSS 0.6%
- Veröffentlicht 29.09.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
- EPSS 0.37%
- Veröffentlicht 19.08.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.
CVE-2009-2859
- EPSS 0.07%
- Veröffentlicht 19.08.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
- EPSS 1.07%
- Veröffentlicht 19.08.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
- EPSS 0.95%
- Veröffentlicht 03.06.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
- EPSS 0.75%
- Veröffentlicht 03.06.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
- EPSS 2.15%
- Veröffentlicht 03.06.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CV...