CVE-2007-3676
published 2008-02-13CVE-2007-3676: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.21%
89.8th percentile
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | <= 8.0 | — |
| ibm | db2 | <= 9.0 | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vvf-4m7g-gc7w: Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2008-6821 [CRITICAL] CWE-119 GHSA-2vvf-4m7g-gc7w: Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
GHSA
GHSA-xxpj-63fc-3w3g: Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9
ghsa_unreviewed·2022-05-03·CVSS 10.0
CVE-2008-3853 [CRITICAL] CWE-119 GHSA-xxpj-63fc-3w3g: Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
GHSA
GHSA-xrxm-c9j3-54pp: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2007-3676 [HIGH] GHSA-xrxm-c9j3-54pp: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2008-02-13
Published