Informix Dynamic Server

Vendor:

First CVE: Jan 27, 2004 · Active for 22 years

50
Total CVEs
More Total CVEs than 98% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Informix Dynamic Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2004
22 years ago
Most Recent CVE
Dec 2, 2025
237 days ago

CVE Severity & Scoring

Informix Dynamic Server50 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local17 (34.0%)
Network4 (8.0%)
Unknown29 (58.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (42.0%)
High0 (0.0%)
Unknown29 (58.0%)
User Interaction
None19 (38.0%)
Unknown29 (58.0%)
Required2 (4.0%)
Privileges Required
Low9 (18.0%)
High9 (18.0%)
None3 (6.0%)
Unknown29 (58.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynam
Mar 5, 201010.057NOYES
Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dyna
Mar 5, 201010.040NOYES
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.
Dec 8, 20129.030NONO
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED ses
Feb 15, 20119.329NONO
Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40
Oct 25, 201010.029NONO
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via
Sep 25, 20129.028NONO
Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote
Oct 23, 20109.028NONO
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCON
Jan 27, 20047.227NOYES
IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.
Dec 2, 20257.826NONO
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 all
Oct 25, 20108.526NONO

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
6.0% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For Informix Dynamic Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.40.xd829.34.0%00
9.40.xc746.43.5%00
9.40_xc729.34.0%00
9.40.xc565.72.5%00
9.40.uc5106.42.9%00
9.40.uc396.32.8%00
9.40.uc2135.92.2%01
9.40.uc1135.92.2%01
9.40.tc5106.42.9%00
9.475.52.3%00
9.329.34.0%00
7.31.xd929.34.0%00
7.31.xd829.34.0%00
7.3137.53.5%00
7.329.34.0%00
15.017.50.4%00
14.1086.70.3%00
12.10157.00.4%00
12.126.70.4%00
11.70.xcn17.80.4%00