CVE-2005-4866
published 2005-12-31CVE-2005-4866: Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.55%
72.3th percentile
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=110495251101381&w=2http://secunia.com/advisories/12733/http://www-1.ibm.com/support/docview.wss?uid=swg1IY61492http://www.nextgenss.com/advisories/db205012005D.txthttp://www.securityfocus.com/bid/11401https://exchange.xforce.ibmcloud.com/vulnerabilities/17613http://marc.info/?l=bugtraq&m=110495251101381&w=2http://secunia.com/advisories/12733/http://www-1.ibm.com/support/docview.wss?uid=swg1IY61492http://www.nextgenss.com/advisories/db205012005D.txthttp://www.securityfocus.com/bid/11401https://exchange.xforce.ibmcloud.com/vulnerabilities/17613
2005-12-31
Published