Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

11,728 CVEs tagged to vendor oracle1,304 Critical, 3,230 High, 6,137 Medium, 1,055 Low, 2 Unrated.

CVE-2002-1089

Published Oct 4, 2002

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in ad…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0856

Published Sep 5, 2002

SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0857

Published Sep 5, 2002

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0858

Published Sep 5, 2002

catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain othe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0509

Published Aug 12, 2002

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0569

Published Jul 3, 2002

Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0571

Published Jul 3, 2002

Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1641

Published May 27, 2002

Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1639

Published Apr 1, 2002

Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1640

Published Apr 1, 2002

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0102

Published Mar 25, 2002

Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0103

Published Mar 25, 2002

An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) runn…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 11,651-11,675 of 11,728 CVEsPage 467 of 470