CVE-2008-3857
- EPSS 0.06%
- Published 28.08.2008 17:41:00
- Last modified 09.04.2025 00:30:58
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by rea...
CVE-2008-3858
- EPSS 1%
- Published 28.08.2008 17:41:00
- Last modified 09.04.2025 00:30:58
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
CVE-2007-5758
- EPSS 0.07%
- Published 16.04.2008 18:05:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF enviro...
CVE-2007-5664
- EPSS 0.03%
- Published 16.04.2008 18:05:00
- Last modified 09.04.2025 00:30:58
db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization...
CVE-2007-5757
- EPSS 0.06%
- Published 13.02.2008 00:00:00
- Last modified 09.04.2025 00:30:58
Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library....
CVE-2007-6053
- EPSS 0.44%
- Published 20.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be cert...
- EPSS 1%
- Published 20.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
CVE-2007-6046
- EPSS 0.05%
- Published 20.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
- EPSS 0.65%
- Published 20.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.
- EPSS 0.76%
- Published 20.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.