Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

11,298 CVEs tagged to vendor oracle1,259 Critical, 3,008 High, 6,009 Medium, 1,020 Low, 2 Unrated.

CVE-2007-2134

Published Apr 18, 2007

Unspecified vulnerability in the HTML Server in Oracle JD Edwards EnterpriseOne SP23_Q1 and 8.96.I1 has unknown impact and local attack vectors, aka JDE01.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1609

Published Mar 22, 2007

Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1506

Published Mar 19, 2007

Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1442

Published Mar 14, 2007

Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1420

Published Mar 12, 2007

MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-7138

Published Mar 7, 2007

SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7141

Published Mar 7, 2007

Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7158

Published Mar 7, 2007

Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7067

Published Mar 2, 2007

Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with inval…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0882

Published Feb 12, 2007

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0423

Published Jan 23, 2007

BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0426

Published Jan 23, 2007

BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0268

Published Jan 17, 2007

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0269

Published Jan 17, 2007

Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0270

Published Jan 17, 2007

Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GE…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0271

Published Jan 17, 2007

Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0272

Published Jan 17, 2007

Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0273

Published Jan 17, 2007

Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Orac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0274

Published Jan 17, 2007

Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0276

Published Jan 17, 2007

Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (D…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0277

Published Jan 17, 2007

Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0278

Published Jan 17, 2007

Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0279

Published Jan 17, 2007

Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 10,851-10,875 of 11,298 CVEsPage 435 of 452