Vulnerabilities > IBM > DB2 > 9.0

DATE CVE VULNERABILITY TITLE RISK
2007-05-10 CVE-2007-2582 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."
network
low complexity
ibm CWE-119
critical
10.0
2007-03-02 CVE-2007-1228 Improper Authentication vulnerability in IBM DB2 8.2/9.0
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
local
ibm unix CWE-287
4.4
2007-02-21 CVE-2007-1027 Link Following vulnerability in IBM DB2 9.0
Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.
local
ibm CWE-59
4.4
2004-09-28 CVE-2003-1052 Unspecified vulnerability in IBM DB2 and DB2 Universal Database
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
local
low complexity
ibm
7.2
2004-09-28 CVE-2003-1051 Command-line Format String vulnerability in IBM DB2 9.0
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
local
low complexity
ibm
7.2
2004-09-28 CVE-2003-1050 Command-Line Argument Buffer Overflow vulnerability in IBM DB2
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
local
low complexity
ibm
7.2