cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 17 of 17
CVE-2014-3095P4LOWCVSS 3.5v9.5v9.5.0.1+32 more2014-09-04
CVE-2014-3095 [LOW] CWE-20 CVE-2014-3095: The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.
nvd
CVE-2006-4257P4MEDIUMCVSS 4.0v8.0v8.1+13 more2006-08-21
CVE-2006-4257 [MEDIUM] CWE-399 CVE-2006-4257: IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a d IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote authenticated users to cause a denial of service (crash) by (1) sending the first ACCSEC command without an RDBNAM parameter during the CONNECT process, or (2) sending crafted SQLJRA packet, which results in a null dereference.
nvd
CVE-2012-0712P4MEDIUMCVSS 4.0v9.5v9.7+1 more2012-03-20
CVE-2012-0712 [MEDIUM] CWE-399 CVE-2012-0712: The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authen The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
nvd
CVE-2010-1560P4MEDIUMCVSS 4.0≤ 9.1v9.12010-04-27
CVE-2010-1560 [MEDIUM] CVE-2010-1560: Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users t Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.
nvd
CVE-2007-1027P4MEDIUMCVSS 4.4v9.02007-02-21
CVE-2007-1027 [MEDIUM] CWE-59 CVE-2007-1027: Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to o Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
nvd
CVE-2010-3740P4MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3740 [MEDIUM] CWE-399 CVE-2010-3740: The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.
nvd
CVE-2010-3736P4MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3736 [MEDIUM] CWE-399 CVE-2010-3736: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the conne Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.
nvd
CVE-2014-6159P4LOWCVSS 3.5v9.7v9.8+2 more2014-11-08
CVE-2014-6159 [LOW] CWE-20 CVE-2014-6159: IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
nvd
CVE-2010-3732P4LOWCVSS 3.5v9.52010-10-05
CVE-2010-3732 [LOW] CWE-20 CVE-2010-3732: The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to caus The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
nvd
CVE-2009-4334P4MEDIUMCVSS 4.6v9.1v9.5+1 more2009-12-16
CVE-2009-4334 [MEDIUM] CWE-264 CVE-2009-4334: The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 b The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.
nvd
CVE-2007-1228P4MEDIUMCVSS 4.4v8.2v9.02007-03-02
CVE-2007-1228 [MEDIUM] CWE-287 CVE-2007-1228: IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "f IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
nvd
CVE-2023-38719P4MEDIUMCVSS 4.4v11.5.82023-10-17
CVE-2023-38719 [MEDIUM] CWE-20 CVE-2023-38719: IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during da IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.
nvd
CVE-2017-1150P4LOWCVSS 3.1v10.1v10.5+1 more2017-03-08
CVE-2017-1150 [LOW] CWE-269 CVE-2017-1150: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow a IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
nvd
CVE-2009-4150P4MEDIUMCVSS 4.6v9.1v9.5+1 more2009-12-02
CVE-2009-4150 [MEDIUM] CWE-264 CVE-2009-4150: dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits executi dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
nvd
CVE-2010-3196P4LOWCVSS 3.5v9.72010-08-31
CVE-2010-3196 [LOW] CWE-264 CVE-2010-3196: IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a d IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
nvd
CVE-2010-3737P4LOWCVSS 3.5v9.52010-10-05
CVE-2010-3737 [LOW] CWE-399 CVE-2010-3737: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote a Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.
nvd
CVE-2010-3735P4LOWCVSS 2.1v9.52010-10-05
CVE-2010-3735 [LOW] CWE-399 CVE-2010-3735: The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote auth The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
nvd
CVE-2005-2073P4LOWCVSS 2.1v8.1.4v8.1.5+7 more2005-06-29
CVE-2005-2073 [LOW] CVE-2005-2073: Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.
nvd
CVE-2011-1373P4LOWCVSS 1.5≤ 9.7.0.4v9.7.0.1+2 more2011-11-09
CVE-2011-1373 [LOW] CVE-2011-1373: Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (ST Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.
nvd
CVE-2014-4805P4LOWCVSS 2.1v10.5v10.5.0.1+2 more2014-09-04
CVE-2014-4805 [LOW] CWE-200 CVE-2014-4805: IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, w IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
nvd
Ibm Db2 vulnerabilities | cvebase