Skip to main content

Vendor archive

oracle CVEs

Beta · best-effort

10,672 CVEs tagged to vendor oracle1,095 Critical, 2,723 High, 5,854 Medium, 998 Low, 2 Unrated.

CVE-2002-1858

Published Dec 31, 2002

Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1882

Published Dec 31, 2002

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1921

Published Dec 31, 2002

The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1923

Published Dec 31, 2002

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities withou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2153

Published Dec 31, 2002

Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2345

Published Dec 31, 2002

Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2347

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1373

Published Dec 23, 2002

Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1264

Published Nov 12, 2002

Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0386

Published Nov 4, 2002

The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1118

Published Oct 28, 2002

TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0969

Published Oct 11, 2002

Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" paramet…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0947

Published Oct 4, 2002

Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary cod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0965

Published Oct 4, 2002

Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1089

Published Oct 4, 2002

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in ad…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0856

Published Sep 5, 2002

SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0857

Published Sep 5, 2002

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0858

Published Sep 5, 2002

catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain othe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0509

Published Aug 12, 2002

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,576-10,600 of 10,672 CVEsPage 424 of 427