cbcvebase.

Ibm Db2 Universal Database vulnerabilities

66 known vulnerabilities affecting ibm/db2_universal_database.

Total CVEs
66
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH22MEDIUM32LOW3

Vulnerabilities

Page 3 of 4
CVE-2007-4418P4MEDIUMCVSS 5.5≤ 8.02007-08-18
CVE-2007-4418 [MEDIUM] CVE-2007-4418: IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authentica IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE: this issue is probably related to CVE-2007-1089, but this is uncertain due to lack of details.
nvd
CVE-2007-5664P4MEDIUMCVSS 6.9v8v9.1+1 more2008-04-16
CVE-2007-5664 [MEDIUM] CWE-59 CVE-2007-5664: db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1 db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
nvd
CVE-2007-4270P4MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4270 [MEDIUM] CVE-2007-4270: Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.
nvd
CVE-2008-3960P4MEDIUMCVSS 5.0≤ 8.2v8.22008-09-11
CVE-2008-3960 [MEDIUM] CWE-20 CVE-2008-3960: Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fix Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
nvd
CVE-2007-6049P4HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6049 [HIGH] CWE-264 CVE-2007-6049: Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknow Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.
nvd
CVE-2005-4736P4MEDIUMCVSS 6.8v8.0v8.1+10 more2005-12-31
CVE-2005-4736 [MEDIUM] CVE-2005-4736: IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a de IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.
nvd
CVE-2007-6046P4HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6046 [HIGH] CVE-2007-6046: Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows l Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
nvd
CVE-2007-4275P4MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4275 [MEDIUM] CVE-2007-4275: Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixp Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db
nvd
CVE-2007-5757P4MEDIUMCVSS 6.9≤ 8.0v9.02008-02-13
CVE-2007-5757 [MEDIUM] CWE-264 CVE-2007-5757: Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.
nvd
CVE-2006-6638P4MEDIUMCVSS 5.0v8.1v8.1.4+11 more2006-12-19
CVE-2006-6638 [MEDIUM] CVE-2006-6638: IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJ IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
nvd
CVE-2008-3858P4MEDIUMCVSS 4.3v9.12008-08-28
CVE-2008-3858 [MEDIUM] CWE-264 CVE-2008-3858: The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cau The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
nvd
CVE-2005-4739P4MEDIUMCVSS 6.8v8.0v8.1+10 more2005-12-31
CVE-2005-4739 [MEDIUM] CVE-2005-4739: IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticate IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.
nvd
CVE-2007-6050P4HIGHCVSS 7.2≤ 9.12007-11-20
CVE-2007-6050 [HIGH] CWE-264 CVE-2007-6050: Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attac Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."
nvd
CVE-2007-4273P4MEDIUMCVSS 4.6≤ 8.0≤ 9.12007-08-18
CVE-2007-4273 [MEDIUM] CWE-134 CVE-2007-4273: IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary direct IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
nvd
CVE-2006-3067P4MEDIUMCVSS 5.0≤ 8.1v8.0+1 more2006-06-19
CVE-2006-3067 [MEDIUM] CVE-2006-3067: Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
nvd
CVE-2006-3066P4MEDIUMCVSS 5.0≤ 8.10v8.0+11 more2006-06-19
CVE-2006-3066 [MEDIUM] CVE-2006-3066: Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allo Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
nvd
CVE-2005-4735P4MEDIUMCVSS 6.8v8.0v8.1+10 more2005-12-31
CVE-2005-4735 [MEDIUM] CVE-2005-4735: IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a de IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.
nvd
CVE-2006-3068P4MEDIUMCVSS 5.0v8.12006-06-19
CVE-2006-3068 [MEDIUM] CWE-399 CVE-2006-3068: IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of s IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
nvd
CVE-2001-1143P4MEDIUMCVSS 5.0v7.02001-07-11
CVE-2001-1143 [MEDIUM] CVE-2001-1143: IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) d IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
nvd
CVE-2003-0827P4MEDIUMCVSS 5.0v7.1v7.22003-10-06
CVE-2003-0827 [MEDIUM] CVE-2003-0827: The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
nvd
Ibm Db2 Universal Database vulnerabilities | cvebase