VYPR

Informix Dynamic Server

by IBM

CVEs (57)

  • CVE-2024-45675HigDec 2, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.

  • CVE-2023-28523HigDec 9, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.

  • CVE-2026-13367HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.

  • CVE-2020-4799HigOct 8, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force ID: 189460.

  • CVE-2019-4253HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root access privileges. IBM X-Force ID: 159941.

  • CVE-2018-1796HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 149426.

  • CVE-2016-0226HigMar 28, 2016
    risk 0.51cvss 7.8epss 0.00

    The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.

  • CVE-2024-49342HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

  • CVE-2025-1991HigJun 28, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

  • CVE-2026-13476HigAug 12, 2026
    risk 0.47cvss 7.3epss 0.01

    IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.

  • CVE-2021-20515MedApr 30, 2021
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.

  • CVE-2018-1636MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.

  • CVE-2018-1635MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.

  • CVE-2018-1634MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.

  • CVE-2018-1633MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.

  • CVE-2018-1632MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.

  • CVE-2018-1631MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.

  • CVE-2018-1630MedAug 20, 2019
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.

  • CVE-2017-1508MedSep 13, 2017
    risk 0.44cvss 6.7epss 0.00

    IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.

  • CVE-2017-1310MedJun 29, 2017
    risk 0.42cvss 6.5epss 0.02

    IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.

Page 1 of 3