cbcvebase.

Ibm Informix Dynamic Server vulnerabilities

50 known vulnerabilities affecting ibm/informix_dynamic_server.

Total CVEs
50
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH14MEDIUM23LOW4

Vulnerabilities

Page 2 of 3
CVE-2016-0226P4HIGHCVSS 7.8v11.70.xcn2016-03-28
CVE-2016-0226 [HIGH] CWE-284 CVE-2016-0226: The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly rest The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
nvd
CVE-2017-1310P4MEDIUMCVSS 6.5v12.102017-06-29
CVE-2017-1310 [MEDIUM] CWE-119 CVE-2017-1310: IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that w IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
nvd
CVE-2021-20515P4MEDIUMCVSS 6.7v14.10v14.12021-04-30
CVE-2021-20515 [MEDIUM] CWE-787 CVE-2021-20515: IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
nvd
CVE-2006-3853P4MEDIUMCVSS 5.1v9.4v9.40.tc5+7 more2006-08-08
CVE-2006-3853 [MEDIUM] CVE-2006-3853: Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, whe Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, when running on Windows, allows remote attackers to execute arbitrary code via a long username.
nvd
CVE-2006-3855P4MEDIUMCVSS 6.5v9.4v9.40.tc5+6 more2006-08-08
CVE-2006-3855 [MEDIUM] CVE-2006-3855: The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated user The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."
nvd
CVE-2018-1635P4MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1635 [MEDIUM] CWE-787 CVE-2018-1635: Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.
nvd
CVE-2018-1636P4MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1636 [MEDIUM] CWE-787 CVE-2018-1636: Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.
nvd
CVE-2018-1633P4MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1633 [MEDIUM] CWE-59 CVE-2018-1633: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.
nvd
CVE-2018-1631P4MEDIUMCVSS 6.7v12.12019-08-20
CVE-2018-1631 [MEDIUM] CWE-59 CVE-2018-1631: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
nvd
CVE-2018-1632P4MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1632 [MEDIUM] CWE-59 CVE-2018-1632: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
nvd
CVE-2018-1630P4MEDIUMCVSS 6.7v12.12019-08-20
CVE-2018-1630 [MEDIUM] CWE-59 CVE-2018-1630: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.
nvd
CVE-2018-1634P4MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1634 [MEDIUM] CWE-59 CVE-2018-1634: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.
nvd
CVE-2017-1508P4MEDIUMCVSS 6.7v12.102017-09-13
CVE-2017-1508 [MEDIUM] CVE-2017-1508: IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
nvd
CVE-2024-49343P4MEDIUMCVSS 5.4v12.10v14.102025-07-28
CVE-2024-49343 [MEDIUM] CWE-80 CVE-2024-49343: IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2007-5956P4HIGHCVSS 7.2≤ 10.002007-11-14
CVE-2007-5956 [HIGH] CWE-22 CVE-2007-5956: Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows loc Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable.
nvd
CVE-2008-0368P4HIGHCVSS 7.2v10.02008-01-19
CVE-2008-0368 [HIGH] CVE-2008-0368: onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbit onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
nvd
CVE-2009-3470P4MEDIUMCVSS 5.0v10.0v10.00.xc1+17 more2009-09-29
CVE-2009-3470 [MEDIUM] CWE-399 CVE-2009-3470: IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failure, and daemon crash) by sending a long password over a JDBC connection.
nvd
CVE-2023-28527P4MEDIUMCVSS 5.5v12.10v14.10+1 more2023-12-09
CVE-2023-28527 [MEDIUM] CWE-122 CVE-2023-28527: IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.
nvd
CVE-2023-28526P4MEDIUMCVSS 5.5v12.10v14.10+1 more2023-12-09
CVE-2023-28526 [MEDIUM] CWE-122 CVE-2023-28526: IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caus IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.
nvd
CVE-2008-0369P4MEDIUMCVSS 6.9v10.002008-01-19
CVE-2008-0369 [MEDIUM] CVE-2008-0369: Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
nvd