CVE-2005-4735
Last modified
CVE-2005-4735 is a vulnerability of currently unknown severity. IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Db2 Universal Database | 8.0 |
| Ibm | Db2 Universal Database | 8.1 |
| Ibm | Db2 Universal Database | 8.1.4 |
| Ibm | Db2 Universal Database | 8.1.5 |
| Ibm | Db2 Universal Database | 8.1.6 |
| Ibm | Db2 Universal Database | 8.1.6c |
| Ibm | Db2 Universal Database | 8.1.7 |
| Ibm | Db2 Universal Database | 8.1.7b |
| Ibm | Db2 Universal Database | 8.1.8 |
| Ibm | Db2 Universal Database | 8.1.8a |
| Ibm | Db2 Universal Database | 8.1.9 |
| Ibm | Db2 Universal Database | 8.1.9a |
References
- http://secunia.com/advisories/17031Exploit, Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IY70808Exploit, Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1LI70817Exploit, Patch
- http://secunia.com/advisories/17031Exploit, Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1IY70808Exploit, Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1LI70817Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4735?
How severe is CVE-2005-4735?
How do I fix CVE-2005-4735?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4729SQL injection vulnerability in show.php in VBZooM Forum allo…
- CVE-2005-4730Unspecified vulnerability in PEAR Text_Password 1.0 has unkn…
- CVE-2005-4731The Next action in PEAR HTML_QuickForm_Controller 1.0.4 incl…
- CVE-2005-4732Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2005-4733NetBSD 2.0 before 20050316 and NetBSD-current before 2005011…
- CVE-2005-4734Stack-based buffer overflow in IISWebAgentIF.dll in RSA Auth…
- CVE-2005-4736IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows …
- CVE-2005-4737IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F410…
- CVE-2005-4738IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F410…
- CVE-2005-4739IBM DB2 Universal Database (UDB) 820 before version 8 FixPak…
- CVE-2005-4740IBM DB2 Universal Database (UDB) 810 before version 8 FixPak…
- CVE-2005-4741NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current befor…
Are you affected by CVE-2005-4735?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
