CVE-2008-0768
published 2008-02-13CVE-2008-0768: Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.46%
90.3th percentile
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | informix_dynamic_server | 10.0 – 10.00.xc8 | — |
| ibm | informix_dynamic_server | 11.10 – 11.10.xc2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
bugzilla·2007-05-29·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
Description of problem:
Contrary to what the documentation says, ALTER privilege on the old table
and CREATE and INSERT privileges on the new table are sufficient for the
user to be able to rename a table.
Version-Release number of selected component (if applicable):
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18.
Discussion:
Upstream bug report: http://bugs.mysql.com/bug.php?id=27515
---
Reporter changed to [email protected] by request of Jay Turner.
---
This issue has been addressed in following products:
Red Hat Linux Enterprise 4
Red Hat Linux Enterprise 5
Red Hat Application Stack v1 for Enterprise Linux AS/ES (v.4)
Via
https://rhn.redhat.com/errata/RHSA-2008-0768.html
h
Bugzilla
CVE-2006-4031 MySQL improper permission revocation
bugzilla·2006-08-11·CVSS 2.1
CVE-2006-4031 [LOW] CVE-2006-4031 MySQL improper permission revocation
CVE-2006-4031 MySQL improper permission revocation
MySQL improper permission revocation
If a user has been granted permissions to create a MERGE table, even
after permissions have been revoked from the parent table, the user
can access the data via the MERGE table.
More information including a patch can be found here:
http://bugs.mysql.com/bug.php?id=15195
Discussion:
moving to security response parent bug
---
This issue was addressed in:
Red Hat Application Stack:
http://rhn.redhat.com/errata/RHSA-2007-0083.html
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0364.html
http://rhn.redhat.com/errata/RHSA-2008-0768.html
http://secunia.com/advisories/28689http://www-01.ibm.com/support/docview.wss?uid=swg21294211http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyhttp://www.securityfocus.com/bid/27485http://www.securitytracker.com/id?1019281http://www.vupen.com/english/advisories/2008/0317https://exchange.xforce.ibmcloud.com/vulnerabilities/40018http://secunia.com/advisories/28689http://www-01.ibm.com/support/docview.wss?uid=swg21294211http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=onlyhttp://www.securityfocus.com/bid/27485http://www.securitytracker.com/id?1019281http://www.vupen.com/english/advisories/2008/0317https://exchange.xforce.ibmcloud.com/vulnerabilities/40018
2008-02-13
Published