Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2007-09-10 CVE-2007-4793 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in xlplm in plm.server.rte in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4792 Buffer Errors vulnerability in IBM AIX 5.3
Buffer overflow in ibstat in devices.common.IBM.ib.rte in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.2
2007-09-10 CVE-2007-4791 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM AIX 5.2/5.3
Buffer overflow in the swcons command in bos.rte.console in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2005-3504 and CVE-2007-0978.
local
low complexity
ibm CWE-119
7.2
2007-08-18 CVE-2007-4423 Buffer Errors vulnerability in IBM DB2 Universal Database 8.0/9.0/9.1
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
network
low complexity
ibm CWE-119
5.0
2007-08-18 CVE-2007-4418 Multiple Unspecified vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors.
network
low complexity
ibm
5.5
2007-08-18 CVE-2007-4417 Multiple Unspecified vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
network
ibm
6.0
2007-08-18 CVE-2007-4276 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2 Universal Database
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.
local
ibm CWE-119
6.9
2007-08-18 CVE-2007-4275 Multiple Unspecified vulnerability in IBM DB2 Universal Database
Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.
local
ibm
6.9
2007-08-18 CVE-2007-4273 USE of Externally-Controlled Format String vulnerability in IBM DB2 Universal Database
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary directories and execute arbitrary code via a "crafted localized message file" that enables a format string attack, possibly involving the (1) OSSEMEMDBG or (2) TRC_LOG_FILE environment variable in db2licd (db2licm).
local
low complexity
ibm CWE-134
4.6
2007-08-18 CVE-2007-4272 Multiple Unspecified vulnerability in IBM DB2 Universal Database
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variable in db2licd (db2licm).
local
ibm
1.9