Informix Dynamic Server
Vendor:
First CVE: Jan 27, 2004 · Active for 22 years
50
Total CVEs
More Total CVEs than 98% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Informix Dynamic Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2004
22 years ago
Most Recent CVE
Dec 2, 2025
237 days ago
CVE Severity & Scoring
Informix Dynamic Server50 CVEs
46%
46%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local17 (34.0%)
Network4 (8.0%)
Unknown29 (58.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (42.0%)
High0 (0.0%)
Unknown29 (58.0%)
User Interaction
None19 (38.0%)
Unknown29 (58.0%)
Required2 (4.0%)
Privileges Required
Low9 (18.0%)
High9 (18.0%)
None3 (6.0%)
Unknown29 (58.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2754HIGH Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynam | Mar 5, 2010 | 10.0 | 57 | NO | YES |
CVE-2009-2753HIGH Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dyna | Mar 5, 2010 | 10.0 | 40 | NO | YES |
CVE-2012-4857HIGH Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement. | Dec 8, 2012 | 9.0 | 30 | NO | NO |
CVE-2011-1033HIGH Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED ses | Feb 15, 2011 | 9.3 | 29 | NO | NO |
CVE-2010-4070HIGH Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40 | Oct 25, 2010 | 10.0 | 29 | NO | NO |
CVE-2012-3334HIGH Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via | Sep 25, 2012 | 9.0 | 28 | NO | NO |
CVE-2010-4053HIGH Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote | Oct 23, 2010 | 9.0 | 28 | NO | NO |
CVE-2004-2131HIGH Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCON | Jan 27, 2004 | 7.2 | 27 | NO | YES |
CVE-2024-45675HIGH IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password. | Dec 2, 2025 | 7.8 | 26 | NO | NO |
CVE-2010-4069HIGH Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 all | Oct 25, 2010 | 8.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
6.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Informix Dynamic Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.40.xd8 | 2 | 9.3 | 4.0% | 0 | 0 |
| 9.40.xc7 | 4 | 6.4 | 3.5% | 0 | 0 |
| 9.40_xc7 | 2 | 9.3 | 4.0% | 0 | 0 |
| 9.40.xc5 | 6 | 5.7 | 2.5% | 0 | 0 |
| 9.40.uc5 | 10 | 6.4 | 2.9% | 0 | 0 |
| 9.40.uc3 | 9 | 6.3 | 2.8% | 0 | 0 |
| 9.40.uc2 | 13 | 5.9 | 2.2% | 0 | 1 |
| 9.40.uc1 | 13 | 5.9 | 2.2% | 0 | 1 |
| 9.40.tc5 | 10 | 6.4 | 2.9% | 0 | 0 |
| 9.4 | 7 | 5.5 | 2.3% | 0 | 0 |
| 9.3 | 2 | 9.3 | 4.0% | 0 | 0 |
| 7.31.xd9 | 2 | 9.3 | 4.0% | 0 | 0 |
| 7.31.xd8 | 2 | 9.3 | 4.0% | 0 | 0 |
| 7.31 | 3 | 7.5 | 3.5% | 0 | 0 |
| 7.3 | 2 | 9.3 | 4.0% | 0 | 0 |
| 15.0 | 1 | 7.5 | 0.4% | 0 | 0 |
| 14.10 | 8 | 6.7 | 0.3% | 0 | 0 |
| 12.10 | 15 | 7.0 | 0.4% | 0 | 0 |
| 12.1 | 2 | 6.7 | 0.4% | 0 | 0 |
| 11.70.xcn | 1 | 7.8 | 0.4% | 0 | 0 |