Vulnerabilities > IBM > DB2 Universal Database

DATE CVE VULNERABILITY TITLE RISK
2007-11-20 CVE-2007-6048 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors.
network
low complexity
linux microsoft unix ibm CWE-264
critical
10.0
2007-11-20 CVE-2007-6047 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.
network
low complexity
linux microsoft unix ibm CWE-264
critical
10.0
2007-11-20 CVE-2007-6046 Privilege Escalation vulnerability in IBM DB2
Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.
local
low complexity
linux microsoft unix ibm
7.2
2007-11-20 CVE-2007-6045 Privilege Escalation vulnerability in IBM DB2
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
network
low complexity
linux microsoft unix ibm
critical
10.0
2007-08-18 CVE-2007-4423 Buffer Errors vulnerability in IBM DB2 Universal Database 8.0/9.0/9.1
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
network
low complexity
ibm CWE-119
5.0
2007-08-18 CVE-2007-4418 Multiple Unspecified vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors.
network
low complexity
ibm
5.5
2007-08-18 CVE-2007-4417 Multiple Unspecified vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
network
ibm
6.0
2007-08-18 CVE-2007-4276 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.
local
ibm CWE-119
6.9
2007-08-18 CVE-2007-4275 Multiple Unspecified vulnerability in IBM DB2 Universal Database
Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.
local
ibm
6.9
2007-08-18 CVE-2007-4273 USE of Externally-Controlled Format String vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
local
low complexity
ibm CWE-134
4.6