Vulnerabilities > IBM > DB2 Universal Database > 8.1

DATE CVE VULNERABILITY TITLE RISK
2007-02-23 CVE-2007-1086 Local Privilege Escalation vulnerability in IBM DB2 Universal Database
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
local
low complexity
hp ibm linux microsoft sun
7.2
2006-12-19 CVE-2006-6638 Remote SQLJRA Packet Denial of Service vulnerability in IBM DB2
IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.
network
low complexity
ibm
5.0
2006-06-19 CVE-2006-3068 Resource Management Errors vulnerability in IBM DB2 Universal Database 8.1
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ...
network
low complexity
ibm CWE-399
5.0
2006-06-19 CVE-2006-3067 Denial-Of-Service vulnerability in IBM DB2 Universal Database 8.0/8.1
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in the (a) REPLACE INTO and (b) INSERT INTO portions of the LOAD command or a (2) large number of values in an IN clause, possibly related to a buffer overflow.
network
low complexity
ibm
5.0
2006-06-19 CVE-2006-3066 Denial of Service vulnerability in IBM DB2 Universal Database
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
network
low complexity
ibm
5.0
2005-12-31 CVE-2005-4868 Incorrect Permission Assignment for Critical Resource vulnerability in IBM DB2 Universal Database
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
local
low complexity
ibm CWE-732
7.1
2005-12-31 CVE-2005-4867 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.
network
ibm CWE-119
critical
9.3
2005-12-31 CVE-2005-4866 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
network
ibm CWE-119
6.8
2005-12-31 CVE-2005-4865 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
network
low complexity
ibm CWE-119
critical
10.0
2005-12-31 CVE-2005-4864 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.
local
low complexity
ibm CWE-119
7.2