Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

11,199 CVEs tagged to vendor oracle1,245 Critical, 2,959 High, 5,979 Medium, 1,014 Low, 2 Unrated.

CVE-2005-2558

Published Aug 16, 2005

Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create use…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2572

Published Aug 16, 2005

MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute ar…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2573

Published Aug 16, 2005

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2371

Published Jul 26, 2005

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2372

Published Jul 26, 2005

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2378

Published Jul 26, 2005

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat paramete…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2379

Published Jul 26, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2291

Published Jul 18, 2005

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2292

Published Jul 18, 2005

Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensit…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2293

Published Jul 18, 2005

Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive informat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2294

Published Jul 18, 2005

Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2093

Published Jul 5, 2005

Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1743

Published May 24, 2005

BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1745

Published May 24, 2005

The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1746

Published May 24, 2005

The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1747

Published May 24, 2005

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1748

Published May 24, 2005

The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1749

Published May 24, 2005

Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1636

Published May 17, 2005

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local user…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1496

Published May 11, 2005

The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1381

Published May 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialP…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1382

Published May 3, 2005

The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1383

Published May 3, 2005

The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a requ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 11,001-11,025 of 11,199 CVEsPage 441 of 448