Unrated severityNVD Advisory· Published Feb 23, 2007· Updated Apr 23, 2026
CVE-2007-1088
CVE-2007-1088
Description
Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
Affected products
20cpe:2.3:a:ibm:db2:8.0:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:ibm:db2:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.0:fp13:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.0:fp14:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.0:fp8:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.0:fp9:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.6c:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.7b:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.8a:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1.9a:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1:fp13:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:8.1:fp14:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www-1.ibm.com/support/docview.wssnvdPatchVendor Advisory
- www.securityfocus.com/bid/22677nvdPatchThird Party AdvisoryVDB Entry
- www.attrition.org/pipermail/vim/2007-August/001765.htmlnvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/32652nvdThird Party AdvisoryVDB Entry
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvdBroken Link
- osvdb.org/40971nvdBroken Link
News mentions
0No linked articles in our index yet.