Ibm Soliddb vulnerabilities

13 known vulnerabilities affecting ibm/soliddb.

Total CVEs
13
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM9LOW1

Vulnerabilities

Page 1 of 1
CVE-2013-3031LOWCVSS 3.5v6.0v6.0.1060+39 more2013-09-09
CVE-2013-3031 [LOW] CWE-119 CVE-2013-3031: A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory access and daemon crash) via a call that includes named arguments and default parameter values, but does no
nvd
CVE-2012-0200MEDIUMCVSS 4.0PoC≤ 6.5.0.8v6.5.0.0+7 more2012-02-21
CVE-2012-0200 [MEDIUM] CVE-2012-0200: The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, whi The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a redundant WHERE condition.
nvd
CVE-2011-4890MEDIUMCVSS 4.0≤ 6.5.0.8v6.5.0.0+8 more2012-02-21
CVE-2011-4890 [MEDIUM] CWE-20 CVE-2011-4890: The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cau The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a ROWNUM condition involving a subquery.
nvd
CVE-2011-1208HIGHCVSS 7.8v4.5.167v4.5.168+29 more2011-05-05
CVE-2011-1208 [HIGH] CVE-2011-1208: IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49) IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.
nvd
CVE-2011-1560CRITICALCVSS 9.3≤ 4.5.180v4.5.167+24 more2011-04-05
CVE-2011-1560 [CRITICAL] CWE-255 CVE-2011-1560: solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6 solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.
nvd
CVE-2010-4055MEDIUMCVSS 5.0PoC≤ 6.5.0.3v4.5.167+23 more2010-10-23
CVE-2010-4055 [MEDIUM] CWE-399 CVE-2010-4055: Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attack Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.
nvd
CVE-2010-4057MEDIUMCVSS 5.0PoC≤ 6.5.0.3v4.5.167+22 more2010-10-23
CVE-2010-4057 [MEDIUM] CWE-189 CVE-2010-4057: solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.
nvd
CVE-2010-4056MEDIUMCVSS 5.0PoC≤ 6.5.0.3v4.5.167+22 more2010-10-23
CVE-2010-4056 [MEDIUM] CVE-2010-4056: solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.
nvd
CVE-2010-2771CRITICALCVSS 10.0≤ 6.5.0.1v4.5.167+20 more2010-07-22
CVE-2010-2771 [CRITICAL] CWE-94 CVE-2010-2771: solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.
nvd
CVE-2008-1708MEDIUMCVSS 4.3≤ 06.00.10182008-04-09
CVE-2008-1708 [MEDIUM] CWE-399 CVE-2008-1708: IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of mem IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of memory to allocate, which allows remote attackers to cause a denial of service (daemon exit) via a packet with a large value in this field.
nvd
CVE-2008-1706MEDIUMCVSS 4.3v06.00.10182008-04-09
CVE-2008-1706 [MEDIUM] CWE-189 CVE-2008-1706: Uncontrolled array index in IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a de Uncontrolled array index in IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large value in a certain 32-bit field.
nvd
CVE-2008-1707MEDIUMCVSS 4.3≤ 06.00.10182008-04-09
CVE-2008-1707 [MEDIUM] CWE-399 CVE-2008-1707: IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (NULL pointe IBM solidDB 06.00.1018 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a packet with an 0x11 value in a certain "type" field.
nvd
CVE-2008-1705MEDIUMCVSS 6.8v06.00.10182008-04-09
CVE-2008-1705 [MEDIUM] CWE-134 CVE-2008-1705: Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows rem Format string vulnerability in the logging function in IBM solidDB 06.00.1018 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) user name, (2) peer name, and possibly unspecified other fields.
nvd