Lucene search

K
cveMitreCVE-2005-4866
HistoryOct 06, 2007 - 9:00 p.m.

CVE-2005-4866

2007-10-0621:00:00
CWE-119
mitre
web.nvd.nist.gov
26
cve-2005-4866
ibm db2
buffer overflow
jdbc
remote code execution

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.022

Percentile

89.8%

Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow.

Affected configurations

Nvd
Node
ibmdb2_universal_databaseMatch7.0aix
OR
ibmdb2_universal_databaseMatch7.0hp-ux
OR
ibmdb2_universal_databaseMatch7.0linux
OR
ibmdb2_universal_databaseMatch7.0solaris
OR
ibmdb2_universal_databaseMatch7.1aix
OR
ibmdb2_universal_databaseMatch7.1hp-ux
OR
ibmdb2_universal_databaseMatch7.1linux
OR
ibmdb2_universal_databaseMatch7.1solaris
OR
ibmdb2_universal_databaseMatch7.1windows
OR
ibmdb2_universal_databaseMatch7.2aix
OR
ibmdb2_universal_databaseMatch7.2hp-ux
OR
ibmdb2_universal_databaseMatch7.2linux
OR
ibmdb2_universal_databaseMatch7.2solaris
OR
ibmdb2_universal_databaseMatch7.2windows
OR
ibmdb2_universal_databaseMatch8.0aix
OR
ibmdb2_universal_databaseMatch8.0hp-ux
OR
ibmdb2_universal_databaseMatch8.0linux
OR
ibmdb2_universal_databaseMatch8.0solaris
OR
ibmdb2_universal_databaseMatch8.0windows
OR
ibmdb2_universal_databaseMatch8.1aix
OR
ibmdb2_universal_databaseMatch8.1hp_ux
OR
ibmdb2_universal_databaseMatch8.1linux
OR
ibmdb2_universal_databaseMatch8.1solaris
OR
ibmdb2_universal_databaseMatch8.1windows
VendorProductVersionCPE
ibmdb2_universal_database7.0cpe:2.3:a:ibm:db2_universal_database:7.0:*:aix:*:*:*:*:*
ibmdb2_universal_database7.0cpe:2.3:a:ibm:db2_universal_database:7.0:*:hp-ux:*:*:*:*:*
ibmdb2_universal_database7.0cpe:2.3:a:ibm:db2_universal_database:7.0:*:linux:*:*:*:*:*
ibmdb2_universal_database7.0cpe:2.3:a:ibm:db2_universal_database:7.0:*:solaris:*:*:*:*:*
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:aix:*:*:*:*:*
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:hp-ux:*:*:*:*:*
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:linux:*:*:*:*:*
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:solaris:*:*:*:*:*
ibmdb2_universal_database7.1cpe:2.3:a:ibm:db2_universal_database:7.1:*:windows:*:*:*:*:*
ibmdb2_universal_database7.2cpe:2.3:a:ibm:db2_universal_database:7.2:*:aix:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.022

Percentile

89.8%

Related for CVE-2005-4866