Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2024-1013

Medium priority

Some fixes available 7 of 8

An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can...

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2011-1145

Low priority
Ignored

The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc
Show less packages

CVE-2018-7485

Medium priority
Not affected

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc Not affected
Show less packages

CVE-2018-7409

Low priority

Some fixes available 13 of 14

In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc Fixed Fixed Fixed Fixed
Show less packages

CVE-2012-2658

Low priority
Ignored

** DISPUTED ** Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since...

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc Ignored
Show less packages

CVE-2012-2657

Low priority
Ignored

** DISPUTED ** Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be...

1 affected package

unixodbc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unixodbc Ignored
Show less packages