← Back

CVE-2006-3854

nvd nist
Published: Aug 17, 2006Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.

Affected (4)

1 product
Informix Dynamic Database Server
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 10.00.tc4
Version 10.00.tc5
Version 9.40.tc7
Version 9.40.tc8

Timeline

No history available yet.