Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

11,134 CVEs tagged to vendor oracle1,237 Critical, 2,914 High, 5,971 Medium, 1,010 Low, 2 Unrated.

CVE-2004-2149

Published Dec 31, 2004

Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placehol…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2229

Published Dec 31, 2004

Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2244

Published Dec 31, 2004

The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and l…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2345

Published Dec 31, 2004

Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users with the ability to invoke SQL to cause a denial of service o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1338

Published Dec 23, 2004

The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1339

Published Dec 23, 2004

SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary S…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1208

Published Dec 3, 2004

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing lo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0835

Published Nov 3, 2004

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0836

Published Nov 3, 2004

Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0837

Published Nov 3, 2004

MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1349

Published Oct 4, 2004

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to v…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0457

Published Sep 28, 2004

The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0637

Published Sep 2, 2004

Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1774

Published Aug 31, 2004

Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0230

Published Aug 18, 2004

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections b…

CVSS 5.0 · Medium

CVE-2004-0543

Published Aug 6, 2004

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1362

Published Aug 4, 2004

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which al…

CVSS 7.5 · High

CVE-2004-1365

Published Aug 4, 2004

Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.

CVSS 4.6 · Medium

CVE-2004-1366

Published Aug 4, 2004

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privilege…

CVSS 4.6 · Medium

CVE-2004-1367

Published Aug 4, 2004

Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the passwor…

CVSS 4.4 · Medium

CVE-2004-1369

Published Aug 4, 2004

The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used…

CVSS 5.0 · Medium

CVE-2004-1370

Published Aug 4, 2004

Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain pri…

CVSS 7.5 · High
Showing 10,976-11,000 of 11,134 CVEsPage 440 of 446