CVE-2008-3853
published 2008-08-28CVE-2008-3853: Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.77%
92.2th percentile
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2_universal_database | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vvf-4m7g-gc7w: Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2008-6821 [CRITICAL] CWE-119 GHSA-2vvf-4m7g-gc7w: Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
GHSA
GHSA-xxpj-63fc-3w3g: Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9
ghsa_unreviewed·2022-05-03·CVSS 10.0
CVE-2008-3853 [CRITICAL] CWE-119 GHSA-xxpj-63fc-3w3g: Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://secunia.com/advisories/29784http://www-01.ibm.com/support/docview.wss?uid=swg1IZ12406http://www-1.ibm.com/support/docview.wss?uid=swg1IZ12379http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601https://exchange.xforce.ibmcloud.com/vulnerabilities/45141ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://secunia.com/advisories/29784http://www-01.ibm.com/support/docview.wss?uid=swg1IZ12406http://www-1.ibm.com/support/docview.wss?uid=swg1IZ12379http://www-1.ibm.com/support/docview.wss?uid=swg21255607http://www.securityfocus.com/bid/29601https://exchange.xforce.ibmcloud.com/vulnerabilities/45141
2008-08-28
Published