
CVE-2008-1966
https://notcve.org/view.php?id=CVE-2008-1966
27 Apr 2008 — Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar. Múltiples desbordamientos de búfer en las rutinas de administración de archivos JAR en el subcomponente BSU JAVA en IBM DB2 versión... • http://osvdb.org/46268 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-3676
https://notcve.org/view.php?id=CVE-2007-3676
12 Feb 2008 — IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698. El Servidor de Administración (DAS) de IBM DB2 Universal Database (UDB) en versión 8 anterior al Fix Pack 16 y versi... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=654 • CWE-399: Resource Management Errors •

CVE-2008-0698
https://notcve.org/view.php?id=CVE-2008-0698
12 Feb 2008 — Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access." Vulnerabilidad de desbordamiento de búfer en BM DB2 UDB anterior a la v8.2 Fixpak 16 tiene un vector de ataque desconocido, y un impacto probablemente relacionado con un "acceso inválido a memoria". • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-0696
https://notcve.org/view.php?id=CVE-2008-0696
12 Feb 2008 — IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors. IBM DB2 UDB antes de 8.2 Fixpak 16 no comprueba la autorización correctamente para la sentencia ALTER TABLE, lo que tiene un impacto desconocido y vectores de ataque. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-0699
https://notcve.org/view.php?id=CVE-2008-0699
12 Feb 2008 — Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors. Vulnerabilidad no específica en el procedimiento ADMIN_SP_C (SYSPROC.ADMIN_SP_C) en DB2 UDB de IBM en versiones anteriores a la 8.2 Fixpak 16, versión 9.1 en versiones anteriores a la FP4a y versión 9.5 en versiones anteriores a laFP1 permite a usuarios autenticados remot... • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT •

CVE-2008-0697
https://notcve.org/view.php?id=CVE-2008-0697
12 Feb 2008 — Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors. Vulnerabilidad no especificada en DB2PD de IBM DB2 UDB anteriores 8.2 Fixpak 16 permite a usuarios locales conseguir privilegios de root a través de vectores no especificados. • ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2007-5652
https://notcve.org/view.php?id=CVE-2007-5652
23 Oct 2007 — IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related. IBM DB2 UDB versión 9.1 anterior a Fixpak 4, no administra apropiadamente el almacenamiento de una lista que contiene información de autenticación, lo que podría permitir a atacantes causar una d... • http://secunia.com/advisories/27177 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-2582 – IBM DB2 DB2JDS Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2007-2582
09 May 2007 — Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow." Múltiples desbordamientos de búfer en el servicio DB2 JDBC Applet Server (DB2JDS) en IBM DB2 versión 9.x y anteriores, permiten que los atacantes remotos (1) ejecuten un código arbi... • http://osvdb.org/40973 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-1228
https://notcve.org/view.php?id=CVE-2007-1228
02 Mar 2007 — IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories. IBM DB2 UDB 8.2 anterior a ixpak 7 (también conocido como fixpack 14), y DB2 9 anterior a Fix Pack 2, sobre UNIX permite al usuario "cercano" acceder a ciertos directorios no autorizados. • http://secunia.com/advisories/24387 • CWE-287: Improper Authentication •

CVE-2007-1087
https://notcve.org/view.php?id=CVE-2007-1087
23 Feb 2007 — IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow. IBM DB2 8.x anterior a 8.1 FixPak 15 y 9.1 anterior a Fix Pack 2 no finaliza adecuadamente ciertas cadenas de entrada, lo cual permite a usuarios locales ejecutar código de su elección a través de variables de entorno no especificadas que disparan un desbordamiento de b... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •