Skip to main content

Vendor/product archive

oracle / oracle8i CVEs

Beta · best-effort

46 CVEs tagged to oracle / oracle8i7 Critical, 18 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2006-0552

Published Feb 4, 2006

Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identif…

CVSS 7.5 · High

CVE-2004-0638

Published Dec 31, 2004

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0637

Published Sep 2, 2004

Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1362

Published Aug 4, 2004

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which al…

CVSS 7.5 · High

CVE-2004-1365

Published Aug 4, 2004

Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.

CVSS 4.6 · Medium

CVE-2004-1366

Published Aug 4, 2004

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privilege…

CVSS 4.6 · Medium

CVE-2004-1367

Published Aug 4, 2004

Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the passwor…

CVSS 4.4 · Medium

CVE-2004-1369

Published Aug 4, 2004

The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used…

CVSS 5.0 · Medium

CVE-2004-1370

Published Aug 4, 2004

Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain pri…

CVSS 7.5 · High

CVE-2004-1371

Published Aug 4, 2004

Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.

CVSS 9.0 · Critical

CVE-2003-0634

Published Aug 27, 2003

Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1118

Published Oct 28, 2002

TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0857

Published Sep 5, 2002

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0858

Published Sep 5, 2002

catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain othe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2