{"api_version":"1","generated_at":"2026-07-23T11:46:44+00:00","cve":"CVE-2008-0768","urls":{"html":"https://cve.report/CVE-2008-0768","api":"https://cve.report/api/cve/CVE-2008-0768.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0768","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0768"},"summary":{"title":"CVE-2008-0768","description":"Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-13 22:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only","name":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Search results","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0317","name":"http://www.vupen.com/english/advisories/2008/0317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only","name":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Search results","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28689","name":"http://secunia.com/advisories/28689","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"IBM Informix Storage Manager XDR Library Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019281","name":"http://www.securitytracker.com/id?1019281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Informix Storage Manager XDR Function Buffer Overflows Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27485","name":"http://www.securityfocus.com/bid/27485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM Informix Storage Manager Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40018","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40018","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0768","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0768","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"768","vulnerable":"1","versionEndIncluding":"10.00.xc8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"informix_dynamic_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"768","vulnerable":"1","versionEndIncluding":"11.10.xc2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"informix_dynamic_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"768","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"informix_storage_manager","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"768","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:54:23.329Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-0317","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0317"},{"name":"IC55041","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only"},{"name":"IC55040","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only"},{"name":"27485","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27485"},{"name":"1019281","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019281"},{"name":"28689","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28689"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211"},{"name":"ibm-ids-xdr-bo(40018)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40018"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-0317","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0317"},{"name":"IC55041","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only"},{"name":"IC55040","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only"},{"name":"27485","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27485"},{"name":"1019281","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019281"},{"name":"28689","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28689"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211"},{"name":"ibm-ids-xdr-bo(40018)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40018"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0768","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-0317","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0317"},{"name":"IC55041","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55041&apar=only"},{"name":"IC55040","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/search.wss?rs=0&q=IC55040&apar=only"},{"name":"27485","refsource":"BID","url":"http://www.securityfocus.com/bid/27485"},{"name":"1019281","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019281"},{"name":"28689","refsource":"SECUNIA","url":"http://secunia.com/advisories/28689"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21294211"},{"name":"ibm-ids-xdr-bo(40018)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40018"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0768","datePublished":"2008-02-13T21:00:00.000Z","dateReserved":"2008-02-13T00:00:00.000Z","dateUpdated":"2024-08-07T07:54:23.329Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-13 22:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndIncluding":"10.00.xc8","matchCriteriaId":"53BCF01B-A64E-4161-8E6E-F0BD0FBB3D42"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*","versionStartIncluding":"11.10","versionEndIncluding":"11.10.xc2","matchCriteriaId":"8625CD11-E4A8-484C-9F35-FBCFC0D290A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:informix_storage_manager:-:*:*:*:*:*:*:*","matchCriteriaId":"B5838FCA-32C4-4DB3-9B83-5BF40916CBBE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"768","Ordinal":"1","Title":"CVE-2008-0768","CVE":"CVE-2008-0768","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"768","Ordinal":"1","NoteData":"Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.","Type":"Description","Title":"CVE-2008-0768"},{"CveYear":"2008","CveId":"768","Ordinal":"2","NoteData":"2008-02-13","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"768","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}