IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
https://exchange.xforce.ibmcloud.com/vulnerabilities/32651
http://www.securityfocus.com/bid/22677
http://www.attrition.org/pipermail/vim/2007-August/001765.html