CVE-2008-0768
Status: ModifiedHigh (10)—
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.46%
- Percentile among all scored CVEs: 91
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-119
References
- http://secunia.com/advisories/28689
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only
- http://www.securityfocus.com/bid/27485
- http://www.securitytracker.com/id?1019281
- http://www.vupen.com/english/advisories/2008/0317
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40018
- http://secunia.com/advisories/28689
- http://www-01.ibm.com/support/docview.wss?uid=swg21294211
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only
- http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only
- http://www.securityfocus.com/bid/27485
- http://www.securitytracker.com/id?1019281
- http://www.vupen.com/english/advisories/2008/0317
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40018
Raw JSON (NVD)
Show
{
"id": "CVE-2008-0768",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-13T22:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/28689",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21294211",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27485",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019281",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0317",
"tags": [
"Permissions Required"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40018",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28689",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21294211",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27485",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019281",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0317",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40018",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de búfer basados en pila y en montículo en los componentes Windows RPC para IBM Informix Storage Manager (ISM), como se utilizan en Informix Dynamic Server (IDS) 10.00.xC8 y anteriores y 11.10.xC2 y anteriores. Permiten a atacantes ejecutar código de su elección a través de peticiones XDR manipuladas."
}
],
"lastModified": "2026-06-16T22:50:18.830",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53BCF01B-A64E-4161-8E6E-F0BD0FBB3D42",
"versionEndIncluding": "10.00.xc8",
"versionStartIncluding": "10.0"
},
{
"criteria": "cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8625CD11-E4A8-484C-9F35-FBCFC0D290A8",
"versionEndIncluding": "11.10.xc2",
"versionStartIncluding": "11.10"
},
{
"criteria": "cpe:2.3:a:ibm:informix_storage_manager:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5838FCA-32C4-4DB3-9B83-5BF40916CBBE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}