SAP SE / Maxdb
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-2450 | SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify… | HIGH | 7.2 | Aug 14, 2018 |
| CVE-2015-2282 | Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver… | HIGH | 7.5 | Jun 2, 2015 |
| CVE-2015-2278 | The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netw… | MEDIUM | 5.0 | Jun 2, 2015 |
| CVE-2010-1185 | Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid len… | HIGH | 10.0 | Mar 29, 2010 |
| CVE-2008-1810 | Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable. | MEDIUM | 4.4 | Aug 1, 2008 |
| CVE-2008-0307 | Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors t… | HIGH | 9.3 | Mar 11, 2008 |
| CVE-2008-0306 | sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to m… | MEDIUM | 6.9 | Mar 11, 2008 |
| CVE-2008-0244 | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other… | HIGH | 10.0 | Jan 12, 2008 |
Showing 1 to 8 of 8 CVEs