Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.8% | — | IBM DB2 Universal Database | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM DB2 Universal Database | 16/11/2005 | 16/6/2026 | IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password. | |
| Modificada | Alta (10) | 1.6% | — | IBM DB2 Universal Database | 27/4/2005 | 16/6/2026 | Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor. | |
| Modificada | Alta (7.2) | 2.2% | — | IBM DB2 Universal Database | 20/10/2004 | 16/6/2026 | DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe. | |
| Modificada | Alta (7.2) | 1.4% | — | IBM DB2 Universal DatabaseAI | 28/9/2004 | 16/6/2026 | Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd. | |
| Modificada | Alta (7.2) | 1.3% | — | IBM DB2IBM DB2 Universal Database | 28/9/2004 | 16/6/2026 | IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs. | |
| Modificada | Media (4.6) | 0.33% | — | IBM DB2 Universal Database | 28/9/2004 | 16/6/2026 | IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files. | |
| Modificada | Alta (7.2) | 0.47% | — | IBM DB2 Universal Database | 28/9/2004 | 16/6/2026 | Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument. | |
| Modificada | Alta (7.2) | 0.49% | — | IBM DB2 Universal Database | 1/9/2004 | 16/6/2026 | Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure. | |
| Modificada | Media (4.6) | 0.56% | — | IBM DB2 Universal Database | 17/11/2003 | 16/6/2026 | IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM DB2 Universal Database | 17/11/2003 | 16/6/2026 | Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command. | |
| Modificada | Alta (7.5) | 2.2% | — | IBM DB2 Universal Database | 17/11/2003 | 16/6/2026 | Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command. | |
| Modificada | Alta (7.2) | 1.1% | — | IBM DB2 Universal Database | 6/10/2003 | 16/6/2026 | Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument. | |
| Modificada | Media (5) | 1.3% | — | IBM DB2 Universal Database | 6/10/2003 | 16/6/2026 | The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523. | |
| Modificada | Alta (7.2) | 1.1% | — | IBM DB2 Universal Database | 6/10/2003 | 16/6/2026 | Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument. | |
| Modificada | Media (5) | 1.6% | — | IBM DB2 Universal Database | 11/7/2001 | 16/6/2026 | IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. | |
| Modificada | Alta (7.5) | 2.8% | — | IBM DB2 Universal Database | 16/2/2001 | 16/6/2026 | IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database. | |
| Modificada | Baja (2.1) | 1.2% | — | IBM DB2 Universal Database | 16/2/2001 | 16/6/2026 | IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. |