Filtered by vendor Ibm Subscriptions
Filtered by product Db2 Universal Database Subscriptions
Total 67 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2004-1372 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
CVE-2001-0051 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
CVE-2001-0052 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
CVE-2005-4866 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.
CVE-2005-3643 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
CVE-2005-4735 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.
CVE-2006-3066 1 Ibm 1 Db2 Universal Database 2025-04-03 N/A
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers to cause a denial of service (application crash) via a long MGRLVLLS message inside of an EXCSAT message when establishing a connection.