
CVE-2009-1239
https://notcve.org/view.php?id=CVE-2009-1239
03 Apr 2009 — IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query. IBM DB2 v9.1 anteriores a FP7 devuelve resultados incorrectos en ciertas situaciones relacionadas con la orden de aplicación de una identificación INNER JOIN y una identificación OUTER JOIN, lo que permitiría a atacantes conseguir información sensible a través d... • http://www-01.ibm.com/support/docview.wss?uid=swg1JR31886 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2008-4692
https://notcve.org/view.php?id=CVE-2008-4692
22 Oct 2008 — The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors. El componete Native Managed Provider para .NET en IBM DB2 v8 anterior a FP17, v9.1 anteior a FP6, y v9.5 anterior a FP2, cuando un "definer" no puede mantener objetos, conserva las vistas (Views) y los disparadores (triggers) sin señalarl... • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT •

CVE-2008-4693
https://notcve.org/view.php?id=CVE-2008-4693
22 Oct 2008 — The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES." El componente SORT/LIST SERVICES en IBM DB2 v9.1 anterior a FP6 y v9.5 anterior a FP2 escribe información sensible en la salida del trazado (trace), lo que permite a atacantes obtener información sensible mediante la lectura de "PASSWORD-RELATED CONNECTION STRING K... • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2008-4691
https://notcve.org/view.php?id=CVE-2008-4691
22 Oct 2008 — Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors. Vulnerabilidad sin especificar en la función SQLNLS_UNPADDEDCHARLEN en el componente New Compiler (también conocido como Starburst derived compiler) en el servidor en IBM DB2 v9.1 anterior a FP6, permite a atacantes remotos provocar una denega... • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT •

CVE-2008-3958
https://notcve.org/view.php?id=CVE-2008-3958
09 Sep 2008 — IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959. IBM DB2 UDB 8 antes del Fixpak 17 permite a atacantes remotos provocar una denegación de servicio (caída de la instancia) mediante una cadena de datos CONNECT/ATTACH manipulada que simula una petición de clien... • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT •

CVE-2008-3959
https://notcve.org/view.php?id=CVE-2008-3959
09 Sep 2008 — IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. IBM DB2 UDB 8.1 anterior FixPak 16, y v8.2 anterior al FixPak 9, permite a atacantes remotos provocar una denegación de servicio (caída de instancia) a través de un flujo de datos CONNECT/ATTACH manipulado que simula una petición cliente connect/a... • http://secunia.com/advisories/29022 •

CVE-2008-3856
https://notcve.org/view.php?id=CVE-2008-3856
28 Aug 2008 — The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors. El componente routine infrastructure en DB2 de IBM versión 8 anterior a FP17, versión 9.1 anterior a FP5 y versión 9.5 anterior a FP1, en Unix y Linux, no cambia la propiedad del proceso db2fmp, que presenta un impacto y vectores de ataque desconocidos. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-1997
https://notcve.org/view.php?id=CVE-2008-1997
28 Apr 2008 — Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699. Vulnerabilidad no especificada en el procedimiento ADMIN_SP_C2 de IBM DB2 8 anterior a FP16, 9.1 anterior a FP4a, y 9.5 anterior a FP1; permite a usuarios autenticados en remoto ejecutar código de su elección mediante vectores desconocidos. NOTA: la ... • http://secunia.com/advisories/29022 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2008-1998
https://notcve.org/view.php?id=CVE-2008-1998
28 Apr 2008 — The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter. El procedimiento NNSTAT (también conocido como SYSPROC.NNSTAT) en IBM DB2 8 versiones anteriores a FP16, 9.1 versiones anteriores a FP4a, y 9.5 versiones anteriores a FP1 en Windows permite a usuarios remotos autenticados sobrescribir ficheros de su elección a través del parámetro log file. • http://secunia.com/advisories/29022 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-1966
https://notcve.org/view.php?id=CVE-2008-1966
27 Apr 2008 — Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar. Múltiples desbordamientos de búfer en las rutinas de administración de archivos JAR en el subcomponente BSU JAVA en IBM DB2 versión... • http://osvdb.org/46268 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •