CVE-2003-1050 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.39% — more likely to be exploited than 72% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-09-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | db2 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM DB2 - 'db2start' Command Line Argument Local Overflow | 2003-11-07 |
| exploit-db | IBM DB2 - 'db2stop' Command Line Argument Local Overflow | 2003-11-07 |
| exploit-db | IBM DB2 - 'db2govd' Command Line Argument Local Overflow | 2003-11-07 |
References
- http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt
- http://www.securityfocus.com/archive/1/343804
- http://www.securityfocus.com/bid/8990
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13633
- http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt
- http://www.securityfocus.com/archive/1/343804
- http://www.securityfocus.com/bid/8990
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13633
→ the Explorer · watch your stack · NVD