sybase records
37 published records for vendor sybase.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 5.4%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-285 Improper Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2008-0912Proof of concept | Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10sybase · mobilink · CWE-119 | Critical10.0 | — | 15.6% | Feb 22, 2008 |
43Plan | CVE-2005-0441No exploit | Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users tsybase · adaptive server enterprise | Critical10.0 | — | 8.5% | Dec 22, 2004 |
42Plan | CVE-2002-2250No exploit | Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter sybase · adaptive server · CWE-119 | Critical10.0 | — | 7.7% | Dec 31, 2002 |
41Plan | CVE-2013-6245No exploit | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.sybase · adaptive server enterprise | Critical10.0 | — | 4.7% | Oct 23, 2013 |
41Plan | CVE-2011-0496No exploit | Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), asybase · appeon for powerbuilder | Critical10.0 | — | 4.5% | Jan 20, 2011 |
41Plan | CVE-2011-2475No exploit | Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybsybase · onebridge mobile data suite · CWE-134 | Critical10.0 | — | 3.7% | Jun 9, 2011 |
41Plan | CVE-2006-3667No exploit | Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vesybase · financial fusion consumer banking solution | Critical10.0 | — | 1.7% | Jul 18, 2006 |
40Plan | CVE-2005-2297Weaponized | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary codsybase · easerver | Medium4.6 | — | 74.2% | Jul 19, 2005 |
39Monitor | CVE-2011-2474Weaponized | Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary fisybase · easerver · CWE-22 | Medium5.0 | — | 63.6% | Jun 9, 2011 |
39Monitor | CVE-2016-7402No exploit | SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system adminisybase · adaptive server enterprise · CWE-264 | Critical9.8 | — | 1.1% | Nov 3, 2016 |
37Monitor | CVE-2013-6866No exploit | SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows sybase · adaptive server enterprise · CWE-94 | Critical9.0 | — | 3.1% | Nov 23, 2013 |
37Monitor | CVE-2013-6865No exploit | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-94 | Critical9.0 | — | 3.1% | Nov 23, 2013 |
37Monitor | CVE-2013-6863No exploit | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-264 | Critical9.0 | — | 1.9% | Nov 23, 2013 |
34Monitor | CVE-2013-6859No exploit | SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.sybase · adaptive server enterprise · CWE-287 | High8.5 | — | 1.6% | Nov 23, 2013 |
32Monitor | CVE-2011-0497No exploit | Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), asybase · appeon for powerbuilder · CWE-22 | High7.8 | — | 2.2% | Jan 20, 2011 |
31Monitor | CVE-2017-5371No exploit | Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series ofsybase · adaptive server enterprise · CWE-20 | High7.5 | — | 3.8% | Jan 23, 2017 |
31Monitor | CVE-2014-6284No exploit | SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and responssybase · adaptive server enterprise · CWE-264 | High7.5 | — | 1.8% | Jun 8, 2015 |
31Monitor | CVE-2013-6862No exploit | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15sybase · adaptive server enterprise | High7.8 | — | 1.3% | Nov 23, 2013 |
31Monitor | CVE-2013-6868No exploit | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-200 | High7.8 | — | 1.1% | Nov 23, 2013 |
30Monitor | CVE-2013-7245No exploit | The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dusybase · adaptive server enterprise · CWE-285 | High7.5 | — | 1.4% | Apr 24, 2018 |
30Monitor | CVE-2015-1310No exploit | SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via unssybase · adaptive server enterprise · CWE-89 | High7.5 | — | 1.2% | Jan 22, 2015 |
28Monitor | CVE-2013-6867No exploit | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to caussybase · adaptive server enterprise | High7.1 | — | 1.5% | Nov 23, 2013 |
27Monitor | CVE-2013-6860No exploit | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15sybase · adaptive server enterprise | Medium6.8 | — | 1.3% | Nov 23, 2013 |
26Monitor | CVE-2014-6283No exploit | SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict acsybase · adaptive server enterprise · CWE-264 | Medium6.5 | — | 1.1% | Oct 17, 2014 |
26Monitor | CVE-2011-5078No exploit | The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin sybase · m-business anywhere · CWE-264 | Medium6.5 | — | 1.0% | Feb 8, 2012 |
- CVE-2008-091245Plan
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10
CriticalCVSS 10.0Proof of conceptEPSS 16%sybase · mobilinkFeb 22, 2008
- CVE-2005-044143Plan
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users t
CriticalCVSS 10.0No exploitEPSS 9%sybase · adaptive server enterpriseDec 22, 2004
- CVE-2002-225042Plan
Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter
CriticalCVSS 10.0No exploitEPSS 8%sybase · adaptive serverDec 31, 2002
- CVE-2013-624541Plan
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.
CriticalCVSS 10.0No exploitEPSS 5%sybase · adaptive server enterpriseOct 23, 2013
- CVE-2011-049641Plan
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), a
CriticalCVSS 10.0No exploitEPSS 5%sybase · appeon for powerbuilderJan 20, 2011
- CVE-2011-247541Plan
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Syb
CriticalCVSS 10.0No exploitEPSS 4%sybase · onebridge mobile data suiteJun 9, 2011
- CVE-2006-366741Plan
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack ve
CriticalCVSS 10.0No exploitEPSS 2%sybase · financial fusion consumer banking solutionJul 18, 2006
- CVE-2005-229740Plan
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary cod
MediumCVSS 4.6WeaponizedEPSS 74%sybase · easerverJul 19, 2005
- CVE-2011-247439Monitor
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary fi
MediumCVSS 5.0WeaponizedEPSS 64%sybase · easerverJun 9, 2011
- CVE-2016-740239Monitor
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system admini
CriticalCVSS 9.8No exploitEPSS 1%sybase · adaptive server enterpriseNov 3, 2016
- CVE-2013-686637Monitor
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows
CriticalCVSS 9.0No exploitEPSS 3%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-686537Monitor
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
CriticalCVSS 9.0No exploitEPSS 3%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-686337Monitor
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
CriticalCVSS 9.0No exploitEPSS 2%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-685934Monitor
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.
HighCVSS 8.5No exploitEPSS 2%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2011-049732Monitor
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), a
HighCVSS 7.8No exploitEPSS 2%sybase · appeon for powerbuilderJan 20, 2011
- CVE-2017-537131Monitor
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of
HighCVSS 7.5No exploitEPSS 4%sybase · adaptive server enterpriseJan 23, 2017
- CVE-2014-628431Monitor
SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and respons
HighCVSS 7.5No exploitEPSS 2%sybase · adaptive server enterpriseJun 8, 2015
- CVE-2013-686231Monitor
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15
HighCVSS 7.8No exploitEPSS 1%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-686831Monitor
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
HighCVSS 7.8No exploitEPSS 1%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-724530Monitor
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database du
HighCVSS 7.5No exploitEPSS 1%sybase · adaptive server enterpriseApr 24, 2018
- CVE-2015-131030Monitor
SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via uns
HighCVSS 7.5No exploitEPSS 1%sybase · adaptive server enterpriseJan 22, 2015
- CVE-2013-686728Monitor
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to caus
HighCVSS 7.1No exploitEPSS 2%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2013-686027Monitor
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15
MediumCVSS 6.8No exploitEPSS 1%sybase · adaptive server enterpriseNov 23, 2013
- CVE-2014-628326Monitor
SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict ac
MediumCVSS 6.5No exploitEPSS 1%sybase · adaptive server enterpriseOct 17, 2014
- CVE-2011-507826Monitor
The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin
MediumCVSS 6.5No exploitEPSS 1%sybase · m-business anywhereFeb 8, 2012