Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-1966

EPSS 1.60% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-1966

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM DB2数据库JAR文件处理多个拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM DB2是美国IBM公司的一套关系型数据库管理系统。该系统的执行环境主要有UNIX、Linux、IBM i、z/OS以及Windows服务器版本。 DB2的RECOVERJAR和REMOVE_JAR过程处理畸形参数数据时存在漏洞,如果用特殊参数调用了RECOVERJAR和REMOVE_JAR过程的话,就可能导致DB2例程崩溃。 任何DB2数据库用户都可以利用这个漏洞,因为默认为这两个过程分配了PUBLIC权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-1966

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1966

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-04-27 · 29 CVEs total

CVE-2008-1980drupal e-publish 跨站脚本攻击漏洞
CVE-2008-1973SubEdit播放器字幕文件处理堆溢出漏洞
CVE-2008-1972Exponent CMS 跨站脚本攻击漏洞
CVE-2008-1971phShoutBox Final 安全绕过漏洞
CVE-2008-1970mucommander 信任管理漏洞
CVE-2008-1969Cezanne 多个跨站脚本攻击漏洞
CVE-2008-1968Cezanne 'FUNID' 参数 多个SQL 注入漏洞
CVE-2008-1967Cezanne Software 'CFLogon.asp'跨站脚本攻击漏洞
CVE-2008-1975E-RESERV index.php SQL注入漏洞
CVE-2008-1974Horde Webmail 'addevent.php'跨站脚本攻击漏洞
CVE-2008-1984CA eTrust Secure Content Manager eCSqdmn远程拒绝服务漏洞
CVE-2008-1983Advanced Electron Forum 'beg'参数 跨站脚本攻击漏洞
CVE-2008-1982WordPress wpSS插件ss_id参数SQL注入漏洞
CVE-2008-1981drupa e-publish 跨站请求伪造漏洞
CVE-2008-1985Digital Hive 'base.php'参数跨站脚本攻击漏洞
CVE-2008-1979CA ARCserve Backup Discovery服务远程拒绝服务漏洞
CVE-2008-1978Drupal Ubercart 跨站脚本攻击漏洞
CVE-2008-1977Drupal多个跨站请求伪造漏洞
CVE-2008-1976Drupal 多个跨站脚本攻击和请求伪造漏洞
CVE-2008-1994Acon 多个缓冲区溢出漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-1966

No comments yet


Leave a comment