VendorsIBMdb2all versions
Vulnerabilities

IBM DB2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

353CVEs
CVE-2022-43929
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2023-02-17 · Modified
7.5EPSS 0.007
CVE-2024-45663
IBM Db2 denial of service
Published 2024-11-21 · Analyzed
7.5EPSS 0.007
CVE-2022-43927
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.006
CVE-2023-27555
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.006
CVE-2023-47152
IBM Db2 information disclosure
Published 2024-01-22 · Modified
7.5EPSS 0.006
CVE-2022-43930
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.005
CVE-2026-86093
IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions
Published 2026-09-10 · Analyzed
7.5EPSS 0.004
CVE-2026-6052
IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables
Published 2026-05-27 · Analyzed
7.5EPSS 0.004
CVE-2025-36442
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
7.5EPSS 0.004
CVE-2024-49350
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
7.5EPSS 0.004
CVE-2025-36070
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
7.5EPSS 0.004
CVE-2026-1718
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure
Published 2026-05-27 · Analyzed
7.5EPSS 0.004
CVE-2024-52903
IBM Db2 denial of service
Published 2025-05-01 · Modified
7.5EPSS 0.003
CVE-2025-2518
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
7.5EPSS 0.003
CVE-2026-6938
IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query
Published 2026-05-27 · Analyzed
7.5EPSS 0.003
CVE-2024-51473
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-33114
IBM Db2 for Linux denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-2533
IBM Db2 for Linux denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2026-6051
IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap
Published 2026-05-27 · Analyzed
7.5EPSS 0.003
CVE-2024-49828
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-36071
IBM Db2 denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2024-47118
IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query
Published 2025-11-07 · Analyzed
7.5EPSS 0.003
CVE-2025-2534
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
7.5EPSS 0.003
CVE-2025-36365
IBM Db2 Privilege Escalation
Published 2026-01-30 · Analyzed
7.5EPSS 0.003
CVE-2025-36010
IBM Db2 for Linux denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.002
CVE-2018-1515
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.
Published 2018-05-25 · Modified
7.4EPSS 0.004
CVE-2017-1297
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Published 2017-06-27 · Modified
7.31 PoCEPSS 0.015
CVE-2016-5995
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
Published 2016-10-01 · Modified
7.3EPSS 0.004
CVE-2023-29257
IBM Db2 code execution
Published 2023-04-26 · Modified
7.2EPSS 0.015
CVE-2003-1050
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
Published 2004-08-20 · Modified
7.23 PoCEPSS 0.014
CVE-2003-1052
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
Published 2004-08-20 · Modified
7.21 PoCEPSS 0.013
CVE-2003-1051
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
Published 2004-08-20 · Modified
7.23 PoCEPSS 0.013
CVE-2023-38003
IBM Db2 command execution
Published 2023-12-04 · Modified
7.2EPSS 0.011
CVE-2014-0907
Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
Published 2014-05-30 · Modified
7.2EPSS 0.007
CVE-2007-1087
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
Published 2007-02-23 · Modified
7.2EPSS 0.005
CVE-2007-1088
Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
Published 2007-02-23 · Modified
7.2EPSS 0.005
CVE-2009-4331
The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.
Published 2009-12-16 · Modified
7.2EPSS 0.005
CVE-2025-36184
IBM Db2 Privilege Escalation
Published 2026-01-30 · Analyzed
7.2EPSS 0.005
CVE-2019-4057
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567.
Published 2019-07-01 · Modified
7.2EPSS 0.005
CVE-2013-3475
Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.
Published 2013-06-05 · Modified
7.2EPSS 0.004
← Prev4 / 9Next →