Ibm

Db2

355 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.52%
  • Veröffentlicht 12.02.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:50:09

Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."

  • EPSS 5.2%
  • Veröffentlicht 12.02.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:50:09

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

  • EPSS 1.79%
  • Veröffentlicht 23.10.2007 21:47:00
  • Zuletzt bearbeitet 16.06.2026 22:46:34

IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of...

  • EPSS 26.99%
  • Veröffentlicht 10.05.2007 00:19:00
  • Zuletzt bearbeitet 16.06.2026 22:39:52

Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an ...

  • EPSS 0.29%
  • Veröffentlicht 02.03.2007 22:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:11

IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.

  • EPSS 0.53%
  • Veröffentlicht 23.02.2007 22:28:00
  • Zuletzt bearbeitet 16.06.2026 22:36:55

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

  • EPSS 0.53%
  • Veröffentlicht 23.02.2007 22:28:00
  • Zuletzt bearbeitet 16.06.2026 22:36:55

Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.

  • EPSS 0.33%
  • Veröffentlicht 21.02.2007 11:28:00
  • Zuletzt bearbeitet 16.06.2026 22:36:47

Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.

  • EPSS 2.13%
  • Veröffentlicht 21.08.2006 20:04:00
  • Zuletzt bearbeitet 16.06.2026 22:28:44

IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA...

  • EPSS 0.76%
  • Veröffentlicht 31.12.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:19:38

The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.