Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2004-1363

Disclosure Date: August 04, 2004 (last updated February 22, 2025)
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
Attacker Value
Unknown

CVE-2004-1365

Disclosure Date: August 04, 2004 (last updated February 22, 2025)
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
0
Attacker Value
Unknown

CVE-2004-1370

Disclosure Date: August 04, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
0
Attacker Value
Unknown

CVE-2004-1707

Disclosure Date: July 30, 2004 (last updated February 22, 2025)
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
0
Attacker Value
Unknown

CVE-2004-1877

Disclosure Date: March 30, 2004 (last updated February 22, 2025)
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
0
Attacker Value
Unknown

CVE-2004-2134

Disclosure Date: January 28, 2004 (last updated February 22, 2025)
Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.
0
Attacker Value
Unknown

CVE-2003-1193

Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.
0
Attacker Value
Unknown

CVE-2002-1631

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
0
Attacker Value
Unknown

CVE-2002-1632

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
0
Attacker Value
Unknown

CVE-2002-1858

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
0