CVE-2008-0698
published 2008-02-12CVE-2008-0698: Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
PriorityP429high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.52%
71.6th percentile
Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | <= 8.0 | — |
| ibm | db2 | <= 9.0 | — |
| ibm | db2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-52f6-v5q4-q9mc: Buffer overflow in the DAS server in IBM DB2 UDB before 8
ghsa_unreviewed·2022-05-03
CVE-2008-0698 [HIGH] CWE-119 GHSA-52f6-v5q4-q9mc: Buffer overflow in the DAS server in IBM DB2 UDB before 8
Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
GHSA
GHSA-xrxm-c9j3-54pp: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2007-3676 [HIGH] GHSA-xrxm-c9j3-54pp: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXThttp://secunia.com/advisories/28771http://www-1.ibm.com/support/docview.wss?uid=swg1IZ05496http://www.securityfocus.com/bid/27681http://www.vupen.com/english/advisories/2008/0401ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXThttp://secunia.com/advisories/28771http://www-1.ibm.com/support/docview.wss?uid=swg1IZ05496http://www.securityfocus.com/bid/27681http://www.vupen.com/english/advisories/2008/0401
2008-02-12
Published