Skip to main content

Vendor/product archive

ibm / db2 CVEs

Beta · best-effort

341 CVEs tagged to ibm / db214 Critical, 96 High, 216 Medium, 15 Low, 0 Unrated.

CVE-2010-3732

Published Oct 5, 2010

The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux,…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3731

Published Oct 5, 2010

Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3475

Published Sep 20, 2010

IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intend…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3474

Published Sep 20, 2010

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3197

Published Aug 31, 2010

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3196

Published Aug 31, 2010

IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent v…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3195

Published Aug 31, 2010

Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors inv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3194

Published Aug 31, 2010

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3193

Published Aug 31, 2010

Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1560

Published Apr 27, 2010

Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might ov…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0472

Published Feb 2, 2010

kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0462

Published Jan 28, 2010

Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement tha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4439

Published Dec 28, 2009

Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instanc…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4438

Published Dec 28, 2009

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4335

Published Dec 16, 2009

Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, relate…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4334

Published Dec 16, 2009

The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4333

Published Dec 16, 2009

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4332

Published Dec 16, 2009

db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4331

Published Dec 16, 2009

The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which h…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4330

Published Dec 16, 2009

Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4329

Published Dec 16, 2009

Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modify…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4328

Published Dec 16, 2009

Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL st…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4327

Published Dec 16, 2009

The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4326

Published Dec 16, 2009

The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4325

Published Dec 16, 2009

The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 341 CVEsPage 12 of 14