Vulnerabilities > IBM > DB2 Universal Database > 7.1

DATE CVE VULNERABILITY TITLE RISK
2006-06-19 CVE-2006-3066 Denial of Service vulnerability in IBM DB2 Universal Database
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
network
low complexity
ibm
5.0
2005-12-31 CVE-2005-4868 Incorrect Permission Assignment for Critical Resource vulnerability in IBM DB2 Universal Database
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
local
low complexity
ibm CWE-732
7.1
2005-12-31 CVE-2005-4867 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.
network
ibm CWE-119
critical
9.3
2005-12-31 CVE-2005-4866 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
network
ibm CWE-119
6.8
2005-12-31 CVE-2005-4865 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
network
low complexity
ibm CWE-119
critical
10.0
2005-12-31 CVE-2005-4864 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.
local
low complexity
ibm CWE-119
7.2
2005-12-31 CVE-2005-4863 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.
local
low complexity
ibm CWE-119
7.2
2005-11-16 CVE-2005-3643 Authentication Bypass vulnerability in IBM DB2 Windows XP Simple File Sharing
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
network
low complexity
ibm
7.5
2005-04-27 CVE-2005-0417 Unspecified vulnerability in IBM DB2 Universal Database
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors.
network
low complexity
ibm
critical
10.0
2004-09-28 CVE-2003-1052 Unspecified vulnerability in IBM DB2 and DB2 Universal Database
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
local
low complexity
ibm
7.2