Vulnerabilities > IBM > DB2 Universal Database > 8.0

DATE CVE VULNERABILITY TITLE RISK
2008-08-28 CVE-2008-3856 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database 8/8.0/9.1
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
network
low complexity
ibm CWE-264
7.5
2007-08-18 CVE-2007-4423 Buffer Errors vulnerability in IBM DB2 Universal Database 8.0/9.0/9.1
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
network
low complexity
ibm CWE-119
5.0
2007-02-23 CVE-2007-1089 Local Security vulnerability in IBM DB2 Universal Database 8.0/9.1
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
local
low complexity
linux microsoft ibm
7.2
2007-02-23 CVE-2007-1086 Local Privilege Escalation vulnerability in IBM DB2 Universal Database
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
local
low complexity
hp ibm linux microsoft sun
7.2
2006-06-19 CVE-2006-3067 Denial-Of-Service vulnerability in IBM DB2 Universal Database 8.0/8.1
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
network
low complexity
ibm
5.0
2006-06-19 CVE-2006-3066 Denial of Service vulnerability in IBM DB2 Universal Database
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
network
low complexity
ibm
5.0
2005-12-31 CVE-2005-4868 Incorrect Permission Assignment for Critical Resource vulnerability in IBM DB2 Universal Database
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
local
low complexity
ibm CWE-732
7.1
2005-12-31 CVE-2005-4867 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.
network
ibm CWE-119
critical
9.3
2005-12-31 CVE-2005-4866 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
network
ibm CWE-119
6.8
2005-12-31 CVE-2005-4865 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
network
low complexity
ibm CWE-119
critical
10.0