Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.
2008-03-18T00:44:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 8.5 (HIGH)
AV:N/AC:L/Au:S/C:N/I:C/A:C
8.0
9.2
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | informix_dynamic_server | 7.3 | Yes |
| Application | ibm | informix_dynamic_server | 7.31.xd8 | Yes |
| Application | ibm | informix_dynamic_server | 7.31.xd9 | Yes |
| Application | ibm | informix_dynamic_server | 9.3 | Yes |
| Application | ibm | informix_dynamic_server | 9.4 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.tc5 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.uc1 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.uc2 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.uc3 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.uc5 | Yes |
| Application | ibm | informix_dynamic_server | 9.40.xd8 | Yes |
| Application | ibm | informix_dynamic_server | 9.40_xc7 | Yes |
| Application | ibm | informix_dynamic_server | 10.0 | Yes |
| Application | ibm | informix_dynamic_server | 10.0.xc3 | Yes |
| Application | ibm | informix_dynamic_server | 10.0.xc4 | Yes |
| Application | ibm | informix_dynamic_server | 10.00.xc7w1 | Yes |
| Application | ibm | informix_dynamic_server | 11.10.xc2 | Yes |