Vulnerabilities > IBM > Informix Dynamic Server

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2018-1633 Link Following vulnerability in IBM Informix Dynamic Server 12.10
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd.
local
low complexity
ibm CWE-59
6.7
2019-08-20 CVE-2018-1632 Link Following vulnerability in IBM Informix Dynamic Server 12.10
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs.
local
low complexity
ibm CWE-59
6.7
2019-08-20 CVE-2018-1631 Link Following vulnerability in IBM Informix Dynamic Server 12.1
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash.
local
low complexity
ibm CWE-59
6.7
2019-08-20 CVE-2018-1630 Link Following vulnerability in IBM Informix Dynamic Server 12.1
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode.
local
low complexity
ibm CWE-59
6.7
2017-09-13 CVE-2017-1508 Unspecified vulnerability in IBM Informix Dynamic Server 12.10
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges.
local
low complexity
ibm linux
6.8
2017-06-29 CVE-2017-1310 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Informix Dynamic Server 12.10
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server.
network
low complexity
ibm CWE-119
4.0
2016-03-28 CVE-2016-0226 Improper Access Control vulnerability in IBM Informix Dynamic Server 11.70.Xcn
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
6.9
2012-12-08 CVE-2012-4857 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Informix Dynamic Server
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
network
low complexity
ibm CWE-119
critical
9.0
2012-09-25 CVE-2012-3334 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Informix Dynamic Server
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.
network
low complexity
ibm CWE-119
critical
9.0
2011-02-15 CVE-2011-1033 Buffer Errors vulnerability in IBM Informix Dynamic Server 11.50
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.
network
ibm CWE-119
critical
9.3