Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

11,134 CVEs tagged to vendor oracle1,237 Critical, 2,914 High, 5,971 Medium, 1,010 Low, 2 Unrated.

CVE-2005-1746

Published May 24, 2005

The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1747

Published May 24, 2005

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1748

Published May 24, 2005

The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1749

Published May 24, 2005

Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1636

Published May 17, 2005

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local user…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1496

Published May 11, 2005

The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1381

Published May 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialP…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1382

Published May 3, 2005

The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1383

Published May 3, 2005

The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a requ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0298

Published May 2, 2005

The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0709

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0710

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary lib…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0711

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to ov…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0873

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1178

Published May 2, 2005

SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1197

Published May 2, 2005

SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0799

Published Mar 15, 2005

MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DO…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0701

Published Mar 7, 2005

Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequenc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0297

Published Jan 18, 2005

SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0638

Published Dec 31, 2004

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2115

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) ac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,951-10,975 of 11,134 CVEsPage 439 of 446