Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-4326

EPSS 0.66% · P71
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-4326

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM DB2 基础设施组件RAND函数信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM DB2是美国IBM公司的一套关系型数据库管理系统。该系统的执行环境主要有UNIX、Linux、IBM i、z/OS以及Windows服务器版本。当数据库分期特征被使用时,IBM DB2 FP5以及FP1中的通用基础设施组件的RAND 纯量函数产生"重复"的返回值,远程攻击者可以在预测值的随机选择基础上几百保护机制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-4326

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4326

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-12-16 · 23 CVEs total

CVE-2009-4335IBM DB2 未明远程漏洞
CVE-2009-4305Moodle SCORM模块处理AICC CRS文件SQL注入漏洞
CVE-2009-4304Moodle 'config.php'随机密码暴力破解漏洞
CVE-2009-4303Moodle 储存stores敏感信息泄露漏洞
CVE-2009-4302Moodle 'index_form.html'cleartext安全权限漏洞
CVE-2009-4301Moodle 'mnet/lib.php 'MNET函数文件执行漏洞
CVE-2009-4300Moodle 多个未明验证插件漏洞
CVE-2009-4299Moodle 'showentry.php '未明安全权限漏洞
CVE-2009-4298Moodle LAMS模块未明信息泄露漏洞
CVE-2009-4297Moodle 多个未明跨站请求伪造漏洞
CVE-2008-7248Ruby on Rails 输入验证错误漏洞
CVE-2009-4138Linux Kernel 'drivers/firewire/ohci.c'空值废除拒绝服务漏洞
CVE-2009-4334IBM DB2 Self Tuning Memory Manager (STMM)组件STMM日志文件拒绝服务漏洞
CVE-2009-4333IBM DB2关联数据服务组件信息泄露漏洞
CVE-2009-4332IBM DB2 Problem Determination组件的db2pd拒绝服务漏洞
CVE-2009-4331IBM DB2安装组件权限许可和访问控制漏洞
CVE-2009-4330IBM DB2 Engine Utilities组件db2licm未明漏洞
CVE-2009-4329IBM DB2 Engine Utilities组件db2ra数据拒绝服务漏洞
CVE-2009-4328IBM DB2 DRDA服务组件未明拒绝服务漏洞
CVE-2009-4327IBM DB2 基础设施组件内存池大小拒绝服务漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-4326

No comments yet


Leave a comment