
CVE-2014-6209
https://notcve.org/view.php?id=CVE-2014-6209
12 Dec 2014 — IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement. IBM DB2 9.5 hasta FP10, 9.7 hasta FP10, 9.8 hasta FP5, 10.1 hasta FP4, y 10.5 anterior a FP5 en Linux, UNIX, y Windows permite a usuarios remotos autenticados causar una denegación de servicio (caída del demonio) mediante la especific... • http://secunia.com/advisories/62092 • CWE-20: Improper Input Validation •

CVE-2014-6097
https://notcve.org/view.php?id=CVE-2014-6097
08 Nov 2014 — IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement. IBM DB2 9.7 anterior a FP10 y 9.8 hasta FP5 en Linux, UNIX, y Windows permite a usuarios remotos autenticados causar una denegación de servicio (caída del demonio) a través de una declaración ALTER TABLE manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT03786 • CWE-20: Improper Input Validation •

CVE-2014-6159
https://notcve.org/view.php?id=CVE-2014-6159
08 Nov 2014 — IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement. IBM DB2 9.7 anterior a FP10, 9.8 hasta FP5, 10.1 hasta FT4, y 10.5 hasta FP4 en Linux, UNIX, y Windows, cuando immediate AUTO_REVAL está habilitado, permite a usuarios remotos autenticados causar una denegación de servicio (caída del demonio) a trav... • http://secunia.com/advisories/62092 • CWE-20: Improper Input Validation •

CVE-2014-4805
https://notcve.org/view.php?id=CVE-2014-4805
04 Sep 2014 — IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring. IBM DB2 10.5 anterior a FP4 en Linux y AIX crea ficheros temporales durante las operaciones CDE table LOAD, lo que permite a usuarios locales obtener información sensible mediante la lectura de un fichero mientras un LOAD está sucediendo. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT03761 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-3095
https://notcve.org/view.php?id=CVE-2014-3095
04 Sep 2014 — The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement. El motor SQL en IBM DB2 9.5 hasta FP10, 9.7 hasta FP9a, 9.8 hasta FP5, 10.1 hasta FP4, y 10.5 anterior a FP4 en Linux, UNIX y Windows permite a usuarios remotos autenticados causar una denegación de servicio (caída del demoni... • http://secunia.com/advisories/58725 • CWE-20: Improper Input Validation •

CVE-2014-3094
https://notcve.org/view.php?id=CVE-2014-3094
04 Sep 2014 — Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement. Desbordamiento de buffer basado en pila en IBM DB2 9.7 hasta FP9a, 9.8 hasta FP5, 10.1 hasta FP4, y 10.5 anterior a FP4 en Linux, UNIX y Windows permite a usuarios remotos autenticados ejecutar código arbitrario a través de una declaración ALTER MODULE manipulada. • http://secunia.com/advisories/58616 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-0907 – IBM DB2 Privilege Escalation
https://notcve.org/view.php?id=CVE-2014-0907
30 May 2014 — Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library. Múltiples vulnerabilidades de búsqueda de ruta no confiable en programas no especificados (1) setuid y (2) setgid en IBM DB2 9.5, 9.7 anterior a FP9a, 9.8, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Linux y UNIX permiten a usuarios locales ganar ... • http://packetstormsecurity.com/files/126940/IBM-DB2-Privilege-Escalation.html •

CVE-2013-6744
https://notcve.org/view.php?id=CVE-2013-6744
30 May 2014 — The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority. La infraestructura Stored Procedure en IBM DB2 9.5, 9.7 anterior a FP9a, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Windows permite a usuarios remotos autenticados ganar privilegios mediante el aprovechamiento del privilegio CONNECT y la autoridad CREATE_EX... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC98849 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-6717
https://notcve.org/view.php?id=CVE-2013-6717
19 Dec 2013 — The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors. El motor de consultas OLAP en IBM DB2 y DB2 Connect 9.7 hasta FP9, 9.8 hasta FP3, y 10.6 hasta FP2, y la pureScale Feature 9.8 para Enterprise Server Edition, permite ausuarios autenticados remotamente... • http://secunia.com/advisories/56451 •

CVE-2013-5466
https://notcve.org/view.php?id=CVE-2013-5466
18 Dec 2013 — The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors. La librería XSLT en IBM DB2 y DB2 Connect 9.5 hasta 10.5, y DB2 pureScale Feature 9.8 para Enterprise Server Edition, permite a usuarios remotos autenticados causar una denegación de servicio a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC97402 •