Ibm Db2 Universal Database vulnerabilities

66 known vulnerabilities affecting ibm/db2_universal_database.

Total CVEs
66
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH22MEDIUM32LOW3

Vulnerabilities

Page 2 of 4
CVE-2007-6050HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6050 [HIGH] CWE-264 CVE-2007-6050: Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attac Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."
nvd
CVE-2007-6052HIGHCVSS 7.8≤ 9.12007-11-20
CVE-2007-6052 [HIGH] CVE-2007-6052: IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow atta IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2007-6046HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6046 [HIGH] CVE-2007-6046: Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows l Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
nvd
CVE-2007-6049HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6049 [HIGH] CWE-264 CVE-2007-6049: Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknow Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
nvd
CVE-2007-4275MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4275 [MEDIUM] CVE-2007-4275: Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixp Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db
nvd
CVE-2007-4417MEDIUMCVSS 6.0≤ 8.0≤ 9.12007-08-18
CVE-2007-4417 [MEDIUM] CVE-2007-4417: IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on method IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
nvd
CVE-2007-4276MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4276 [MEDIUM] CWE-119 CVE-2007-4276: Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attacke Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.
nvd
CVE-2007-4273MEDIUMCVSS 4.6≤ 8.0≤ 9.12007-08-18
CVE-2007-4273 [MEDIUM] CWE-134 CVE-2007-4273: IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary direct IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
nvd
CVE-2007-4270MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4270 [MEDIUM] CVE-2007-4270: Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.
nvd
CVE-2007-4418MEDIUMCVSS 5.5≤ 8.02007-08-18
CVE-2007-4418 [MEDIUM] CVE-2007-4418: IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authentica IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
nvd
CVE-2007-4423MEDIUMCVSS 5.0v8.0v9.0+1 more2007-08-18
CVE-2007-4423 [MEDIUM] CWE-119 CVE-2007-4423: Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fi Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
nvd
CVE-2007-4272LOWCVSS 1.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4272 [LOW] CVE-2007-4272: Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variabl
nvd
CVE-2007-4271LOWCVSS 2.1≤ 8.0≤ 9.12007-08-18
CVE-2007-4271 [LOW] CWE-22 CVE-2007-4271: Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows l Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.
nvd
CVE-2007-1086HIGHCVSS 7.2v8.0v8.1+13 more2007-02-23
CVE-2007-1086 [HIGH] CVE-2007-1086: Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
nvd
CVE-2007-1089HIGHCVSS 7.2≤ 9.1v9.12007-02-23
CVE-2007-1089 [HIGH] CVE-2007-1089: IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privile IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
nvd
CVE-2006-6638MEDIUMCVSS 5.0v8.1v8.1.4+11 more2006-12-19
CVE-2006-6638 [MEDIUM] CVE-2006-6638: IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJ IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
nvd
CVE-2006-3068MEDIUMCVSS 5.0v8.12006-06-19
CVE-2006-3068 [MEDIUM] CWE-399 CVE-2006-3068: IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of s IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
nvd
CVE-2006-3067MEDIUMCVSS 5.0≤ 8.1v8.0+1 more2006-06-19
CVE-2006-3067 [MEDIUM] CVE-2006-3067: Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
nvd
CVE-2006-3066MEDIUMCVSS 5.0≤ 8.10v8.0+11 more2006-06-19
CVE-2006-3066 [MEDIUM] CVE-2006-3066: Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allo Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
nvd
CVE-2005-4865CRITICALCVSS 10.0v7.0v7.1+3 more2005-12-31
CVE-2005-4865 [CRITICAL] CWE-119 CVE-2005-4865: Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitr Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
nvd