Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm db2 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2010-3194
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows malicious users to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
Ibm Db2 9.1
Ibm Db2 9.5
Ibm Db2 9.7
7.5
CVSSv2
CVE-2009-4333
The Relational Data Services component in IBM DB2 9.5 before FP5 allows malicious users to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
Ibm Db2 9.5
7.5
CVSSv2
CVE-2009-3471
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
Ibm Db2 8.0
Ibm Db2 9.1
Ibm Db2 9.5
7.5
CVSSv2
CVE-2008-3958
IBM DB2 UDB 8 before Fixpak 17 allows remote malicious users to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incom...
Ibm Db2 8.0
Ibm Db2
7.5
CVSSv2
CVE-2008-3856
The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.
Ibm Db2 Universal Database 9.1
Ibm Db2 Universal Database 8.0
Ibm Db2 Universal Database
Ibm Db2 Universal Database 8
7.5
CVSSv2
CVE-2008-0696
IBM DB2 UDB prior to 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
Ibm Db2 8.2 Fixpack15
7.5
CVSSv2
CVE-2007-5090
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows malicious users to corrupt data via unspecified vectors.
Ibm Rational Clearquest 5.00
Ibm Rational Clearquest 5.20
Ibm Rational Clearquest 6.00
Ibm Rational Clearquest 6.12
Ibm Rational Clearquest 6.13
Ibm Rational Clearquest 6.14
Ibm Rational Clearquest 6.15
Ibm Rational Clearquest 6.16
Ibm Rational Clearquest 7.0
Ibm Rational Clearquest 7.0.0.1
Ibm Rational Clearquest 7.0.1
7.5
CVSSv2
CVE-2005-4737
IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.
Ibm Db2 Universal Database 8.1.7
Ibm Db2 Universal Database 8.1.7b
Ibm Db2 Universal Database 8.1.8
Ibm Db2 Universal Database 8.1.8a
Ibm Db2 Universal Database 8.0
Ibm Db2 Universal Database 8.1.5
Ibm Db2 Universal Database 8.1.6c
Ibm Db2 Universal Database 8.1.9
Ibm Db2 Universal Database 8.1
Ibm Db2 Universal Database 8.1.4
Ibm Db2 Universal Database 8.1.6
Ibm Db2 Universal Database 8.1.9a
7.5
CVSSv2
CVE-2005-3643
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote malicious users to bypass authentication and log on to the guest account without supplying a password.
Ibm Db2 Universal Database 7.2
Ibm Db2 Universal Database 8.1.4
Ibm Db2 Universal Database 8.1.8a
Ibm Db2 Universal Database 8.1.9a
Ibm Db2 Universal Database 8.1.5
Ibm Db2 Universal Database 8.1.6
Ibm Db2 Universal Database 8.1.6c
Ibm Db2 Universal Database 8.1.7
Ibm Db2 Universal Database 8.1.7b
Ibm Db2 Universal Database 8.1
Ibm Db2 Universal Database 7.1
Ibm Db2 Universal Database 8.0
Ibm Db2 Universal Database 8.1.8
Ibm Db2 Universal Database 8.1.9
7.5
CVSSv2
CVE-2003-0836
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.
Ibm Db2 Universal Database 8.1
Ibm Db2 Universal Database 7.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »