cbcvebase.
CVE-2007-1087
published 2007-02-23

CVE-2007-1087: IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary…

PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
40.8th percentile
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

Affected

13 ranges
VendorProductVersion rangeFixed in
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
ibmdb2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.