NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3716 | CVE-2008-3854 | Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function. | 2 | 7.8 | High | 2017-01-03 | 2011-09-06 | View | |
3717 | CVE-2008-3855 | Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-07 | View | |
3718 | CVE-2008-3856 | The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-08-12 | View | |
3719 | CVE-2008-3857 | The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-07 | View | |
3720 | CVE-2008-3858 | The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request. | 2 | 4.3 | Medium | 2017-01-03 | 2008-11-15 | View |
Page 744 of 17672, showing 5 records out of 88360 total, starting on record 3716, ending on 3720