Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2004-1707

Disclosure Date: July 30, 2004 (last updated February 22, 2025)
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
0
Attacker Value
Unknown

CVE-2003-0634

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.
0
Attacker Value
Unknown

CVE-2003-0222

Disclosure Date: May 12, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
0
Attacker Value
Unknown

CVE-2002-1118

Disclosure Date: October 28, 2002 (last updated February 22, 2025)
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.
0
Attacker Value
Unknown

CVE-2002-0567

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
0
Attacker Value
Unknown

CVE-2000-1180

Disclosure Date: January 09, 2001 (last updated February 22, 2025)
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.
0
Attacker Value
Unknown

CVE-2000-0986

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.
0
Attacker Value
Unknown

CVE-2000-0206

Disclosure Date: March 05, 2000 (last updated February 22, 2025)
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-1999-0888

Disclosure Date: August 16, 1999 (last updated February 22, 2025)
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
0
Attacker Value
Unknown

CVE-1999-0711

Disclosure Date: April 29, 1999 (last updated February 22, 2025)
The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.
0