cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 17 of 18
CVE-2013-5466P4MEDIUMCVSS 4.0v9.5v9.7+3 more2013-12-18
CVE-2013-5466 [MEDIUM] CVE-2013-5466: The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.
nvd
CVE-2017-1434P4MEDIUMCVSS 4.7v11.1.0.02017-09-12
CVE-2017-1434 [MEDIUM] CWE-200 CVE-2017-1434: IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.
nvd
CVE-2009-4329P4MEDIUMCVSS 4.0v9.52009-12-16
CVE-2009-4329 [MEDIUM] CVE-2009-4329: Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility.
nvd
CVE-2009-4328P4MEDIUMCVSS 4.0v9.52009-12-16
CVE-2009-4328 [MEDIUM] CVE-2009-4328: Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote aut Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.
nvd
CVE-2014-6097P4MEDIUMCVSS 4.0v9.7v9.82014-11-08
CVE-2014-6097 [MEDIUM] CWE-20 CVE-2014-6097: IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
nvd
CVE-2005-4871P4MEDIUMCVSS 4.3v8.12005-12-31
CVE-2005-4871 [MEDIUM] CWE-264 CVE-2005-4871: Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, w Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.
nvd
CVE-2020-4414P4MEDIUMCVSS 4.4v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4414 [MEDIUM] CVE-2020-4414: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of servic
nvd
CVE-2017-1520P4LOWCVSS 3.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1520 [LOW] CWE-287 CVE-2017-1520: IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
nvd
CVE-2009-1906P4MEDIUMCVSS 4.3v9.1v9.52009-06-03
CVE-2009-1906 [MEDIUM] CVE-2009-1906: The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.
nvd
CVE-2008-1966P4MEDIUMCVSS 4.0v8.0v9.5+1 more2008-04-27
CVE-2008-1966 [MEDIUM] CWE-119 CVE-2008-1966: Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IB Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_ja
nvd
CVE-2009-2859P4MEDIUMCVSS 4.6≤ 8.1v8.12009-08-19
CVE-2009-2859 [MEDIUM] CWE-264 CVE-2009-2859: IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command. IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
nvd
CVE-2014-3095P4LOWCVSS 3.5v9.5v9.5.0.1+32 more2014-09-04
CVE-2014-3095 [LOW] CWE-20 CVE-2014-3095: The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.
nvd
CVE-2012-0712P4MEDIUMCVSS 4.0v9.5v9.7+1 more2012-03-20
CVE-2012-0712 [MEDIUM] CWE-399 CVE-2012-0712: The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authen The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
nvd
CVE-2009-4439P4MEDIUMCVSS 4.0v9.52009-12-28
CVE-2009-4439 [MEDIUM] CVE-2009-4439: Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 bef Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query.
nvd
CVE-2010-1560P4MEDIUMCVSS 4.0≤ 9.1v9.12010-04-27
CVE-2010-1560 [MEDIUM] CVE-2010-1560: Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users t Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.
nvd
CVE-2006-4257P4MEDIUMCVSS 4.0v8.0v8.1+13 more2006-08-21
CVE-2006-4257 [MEDIUM] CWE-399 CVE-2006-4257: IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a d IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
nvd
CVE-2007-1027P4MEDIUMCVSS 4.4v9.02007-02-21
CVE-2007-1027 [MEDIUM] CWE-59 CVE-2007-1027: Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to o Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
nvd
CVE-2010-3740P4MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3740 [MEDIUM] CWE-399 CVE-2010-3740: The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.
nvd
CVE-2010-3736P4MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3736 [MEDIUM] CWE-399 CVE-2010-3736: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the conne Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.
nvd
CVE-2014-6159P4LOWCVSS 3.5v9.7v9.8+2 more2014-11-08
CVE-2014-6159 [LOW] CWE-20 CVE-2014-6159: IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
nvd
Ibm Db2 vulnerabilities | cvebase