CVE-2009-0172
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 8.5%
from disclosure to weapon77 days
Published on NVDJan 16
1st PoC+77d
exploitation probability
8.5%top 6% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/8344⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXTftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXTftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXThttp://secunia.com/advisories/33529http://securitytracker.com/id?1021591https://exchange.xforce.ibmcloud.com/vulnerabilities/47931http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696http://www-01.ibm.com/support/docview.wss?uid=swg21363936http://www-1.ibm.com/support/docview.wss?uid=swg1IZ36534http://www-1.ibm.com/support/docview.wss?uid=swg1IZ37697http://www.securityfocus.com/bid/33258http://www.vupen.com/english/advisories/2009/0137