Vulnerabilities (CVE)

Vendor filter

Oracle Subscribe

Product filter

Solaris Subscribe

Filter

6114 total CVE
CVE Vendors Products Updated CVSS
CVE-2002-1858 1 Oracle 1 Application Server 2008-09-05 5.0
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to...
CVE-2002-1641 1 Oracle 1 Application Server Web Cache 2008-09-05 10.0
Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.
CVE-2002-1631 1 Oracle 1 Application Server 2008-09-05 7.5
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
CVE-2002-1089 1 Oracle 2 Reports, Application Server 2008-09-05 5.0
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
CVE-2002-0965 1 Oracle 1 Oracle9i 2008-09-05 7.5
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a...
CVE-2002-0947 1 Oracle 2 Reports, Application Server 2008-09-05 7.5
Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.
CVE-2002-0571 1 Oracle 1 Oracle9i 2008-09-05 7.5
Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.
CVE-2002-0509 1 Oracle 1 Oracle9i 2008-09-05 5.0
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.
CVE-2001-1321 1 Oracle 1 Internet Directory 2008-09-05 7.5
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1217 1 Oracle 1 Application Server 2008-09-05 5.0
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
CVE-2001-1216 1 Oracle 1 Application Server 2008-09-05 7.5
Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
CVE-2001-0943 1 Oracle 1 Database Server 2008-09-05 7.2
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan...
CVE-2000-1235 1 Oracle 1 Application Server 2008-09-05 5.0
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
CVE-1999-0784 1 Oracle 1 Database Server 2008-09-05 5.0
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.