Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Db2 Universal Database
Total 67 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4865 1 Ibm 1 Db2 Universal Database 2025-04-03 10.0 HIGH N/A
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
CVE-2005-4868 2 Ibm, Microsoft 2 Db2 Universal Database, Windows 2025-04-03 2.1 LOW 7.1 HIGH
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.
CVE-2006-3068 1 Ibm 1 Db2 Universal Database 2025-04-03 5.0 MEDIUM N/A
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the package name/creator," which leads to a "memory overwrite."
CVE-2006-3066 1 Ibm 1 Db2 Universal Database 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.
CVE-2005-4736 1 Ibm 1 Db2 Universal Database 2025-04-03 6.8 MEDIUM N/A
IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.
CVE-2004-0795 1 Ibm 1 Db2 Universal Database 2025-04-03 7.2 HIGH N/A
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
CVE-2005-3643 1 Ibm 1 Db2 Universal Database 2025-04-03 7.5 HIGH N/A
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.