Page 3 of 96 results (0.003 seconds)

CVSS: 7.2EPSS: 0%CPEs: 18EXPL: 0

Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library. Múltiples vulnerabilidades de búsqueda de ruta no confiable en programas no especificados (1) setuid y (2) setgid en IBM DB2 9.5, 9.7 anterior a FP9a, 9.8, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Linux y UNIX permiten a usuarios locales ganar privilegios root a través de una libraría caballo de troya. • http://packetstormsecurity.com/files/126940/IBM-DB2-Privilege-Escalation.html http://seclists.org/fulldisclosure/2014/Jun/7 http://secunia.com/advisories/59451 http://secunia.com/advisories/59463 http://secunia.com/advisories/60482 http://www-01.ibm.com/support/docview.wss?uid=isg400001841 http://www-01.ibm.com/support/docview.wss?uid=isg400001843 http://www-01.ibm.com/support/docview.wss?uid=swg1IT00627 http://www-01.ibm.com/support/docview.wss?uid=swg1IT00684 http://www-01. •

CVSS: 8.5EPSS: 0%CPEs: 19EXPL: 0

The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority. La infraestructura Stored Procedure en IBM DB2 9.5, 9.7 anterior a FP9a, 10.1 anterior a FP3a y 10.5 anterior a FP3a en Windows permite a usuarios remotos autenticados ganar privilegios mediante el aprovechamiento del privilegio CONNECT y la autoridad CREATE_EXTERNAL_ROUTINE. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC98849 http://www-01.ibm.com/support/docview.wss?uid=swg1IC99478 http://www-01.ibm.com/support/docview.wss?uid=swg1IC99480 http://www-01.ibm.com/support/docview.wss?uid=swg1IC99481 http://www.ibm.com/support/docview.wss? • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.0EPSS: 0%CPEs: 11EXPL: 0

The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors. La librería XSLT en IBM DB2 y DB2 Connect 9.5 hasta 10.5, y DB2 pureScale Feature 9.8 para Enterprise Server Edition, permite a usuarios remotos autenticados causar una denegación de servicio a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IC97402 http://www-01.ibm.com/support/docview.wss?uid=swg1IC97470 http://www-01.ibm.com/support/docview.wss?uid=swg1IC97471 http://www-01.ibm.com/support/docview.wss?uid=swg1IC97472 http://www-01.ibm.com/support/docview.wss? •

CVSS: 7.2EPSS: 0%CPEs: 11EXPL: 0

Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors. Desbordamiento de búfer basado en pila en db2aud en Audit Facility de IBM DB2 y DB2 Connect v9.1, v9.5, v9.7, v9.8 y v10.1, como se utiliza en Smart System Analytics 7600 y otros productos, permite a usuarios locales conseguir privilegios a través de vectores no especificados. • http://secunia.com/advisories/52663 http://secunia.com/advisories/53704 http://www-01.ibm.com/support/docview.wss?uid=swg1IC92463 http://www-01.ibm.com/support/docview.wss?uid=swg1IC92495 http://www-01.ibm.com/support/docview.wss?uid=swg1IC92496 http://www-01.ibm.com/support/docview.wss?uid=swg1IC92498 http://www-01.ibm.com/support/docview.wss? • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 8.5EPSS: 13%CPEs: 11EXPL: 0

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure. Desbordamiento de búfer basado en pila en la infraestructura SQL/PSM (alias SQL Persistent Stored Module) Stored Procedure (SP) en IBM DB2 v9.1, v9.5, v9.7 antes de FP7, v9.8, y v10.1, podría permitir a usuarios remotos autenticados ejecutar código de su elección depurando un procedimiento almacenado. • http://osvdb.org/86414 http://www-01.ibm.com/support/docview.wss?uid=swg1IC86765 http://www-01.ibm.com/support/docview.wss?uid=swg1IC86781 http://www-01.ibm.com/support/docview.wss?uid=swg1IC86782 http://www-01.ibm.com/support/docview.wss?uid=swg1IC86783 http://www-01.ibm.com/support/docview.wss? • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •