VYPR
Unrated severityNVD Advisory· Published Feb 23, 2007· Updated Apr 23, 2026

CVE-2007-1087

CVE-2007-1087

Description

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.

Affected products

20
  • IBM/Db220 versions
    cpe:2.3:a:ibm:db2:8.0:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:ibm:db2:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp13:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp14:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp8:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp9:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.6c:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.7b:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.8a:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1.9a:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1:fp13:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.1:fp14:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.