VendorsIBMinformix_dynamic_serverall versions
Vulnerabilities

IBM Informix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2009-2754
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.
Published 2010-03-05 · Modified
10.01 PoCEPSS 0.403
CVE-2009-2753
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size.
Published 2010-03-05 · Modified
10.01 PoCEPSS 0.109
CVE-2010-4070
Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before 10.00.xC8, and 11.10 before 11.10.xC2 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted parameter size, aka idsdb00146931, idsdb00146930, idsdb00146929, and idsdb00138308.
Published 2010-10-25 · Modified
10.0EPSS 0.051
CVE-2008-0768
Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.
Published 2008-02-13 · Modified
10.0EPSS 0.045
CVE-2008-0949
Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet.
Published 2008-03-18 · Modified
10.0EPSS 0.026
CVE-2011-1033
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.
Published 2011-02-14 · Modified
9.3EPSS 0.048
CVE-2010-4053
Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute arbitrary code via a crafted EXPLAIN directive, aka idsdb00154125 and idsdb00154243.
Published 2010-10-22 · Modified
9.0EPSS 0.046
CVE-2012-4857
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
Published 2012-12-08 · Modified
9.0EPSS 0.046
CVE-2012-3334
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.
Published 2012-09-25 · Modified
9.0EPSS 0.037
CVE-2026-13361
IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution
Published 2026-08-12 · Analyzed
8.8EPSS 0.003
CVE-2008-0727
Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.
Published 2008-03-18 · Modified
8.5EPSS 0.052
CVE-2010-4069
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenticated users to execute arbitrary code via long DBINFO keyword arguments in a SQL statement, aka idsdb00165017, idsdb00165019, idsdb00165021, idsdb00165022, and idsdb00165023.
Published 2010-10-25 · Modified
8.5EPSS 0.039
CVE-2023-28523
IBM Informix Dynamic Server buffer overflow
Published 2023-12-09 · Modified
8.4EPSS 0.003
CVE-2024-45675
IBM Informix Dynamic Server Authentication Bypass
Published 2025-12-02 · Analyzed
8.4EPSS 0.001
CVE-2018-1635
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1636
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1633
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1634
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1632
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1630
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2018-1631
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
Published 2019-08-20 · Modified
8.2EPSS 0.004
CVE-2019-4253
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root access privileges. IBM X-Force ID: 159941.
Published 2019-08-20 · Modified
7.8EPSS 0.004
CVE-2016-0226
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
Published 2016-03-28 · Modified
7.8EPSS 0.004
CVE-2020-4799
IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force ID: 189460.
Published 2020-10-08 · Modified
7.8EPSS 0.004
CVE-2018-1796
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 149426.
Published 2019-08-20 · Modified
7.8EPSS 0.004
CVE-2026-13367
IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
Published 2026-08-12 · Analyzed
7.8EPSS 0.001
CVE-2006-3862
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).
Published 2006-08-08 · Modified
7.5EPSS 0.037
CVE-2025-1991
IBM Informix Dynamic Server denial of service
Published 2025-06-28 · Analyzed
7.5EPSS 0.004
CVE-2024-49342
IBM Informix Dynamic Server information disclosure
Published 2025-07-28 · Analyzed
7.5EPSS 0.003
CVE-2026-13476
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
Published 2026-08-12 · Analyzed
7.3EPSS 0.006
CVE-2004-2131
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.
Published 2005-05-27 · Modified
7.22 PoCEPSS 0.014
CVE-2007-5956
Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable.
Published 2007-11-14 · Modified
7.2EPSS 0.005
CVE-2008-0368
onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
Published 2008-01-18 · Modified
7.2EPSS 0.003
CVE-2008-0369
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
Published 2008-01-18 · Modified
6.9EPSS 0.003
CVE-2017-1508
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
Published 2017-09-13 · Modified
6.8EPSS 0.003
CVE-2021-20515
IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
Published 2021-04-30 · Modified
6.7EPSS 0.003
CVE-2006-3855
The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."
Published 2006-08-08 · Modified
6.5EPSS 0.019
CVE-2017-1310
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
Published 2017-06-29 · Modified
6.5EPSS 0.017
CVE-2023-28527
IBM Informix Dynamic Server buffer overflow
Published 2023-12-09 · Modified
6.2EPSS 0.002
CVE-2023-28526
IBM Informix Dynamic Server buffer overflow
Published 2023-12-09 · Modified
6.2EPSS 0.002
1 / 2Next →