Show filters
90 Total Results
Displaying 81-90 of 90
Sort by:
Attacker Value
Unknown
CVE-2004-1707
Disclosure Date: July 30, 2004 (last updated February 22, 2025)
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
0
Attacker Value
Unknown
CVE-2003-0222
Disclosure Date: May 12, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
0
Attacker Value
Unknown
CVE-2003-0095
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.
0
Attacker Value
Unknown
CVE-2003-0096
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.
0
Attacker Value
Unknown
CVE-2002-0840
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0
Attacker Value
Unknown
CVE-2002-0856
Disclosure Date: September 05, 2002 (last updated February 22, 2025)
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
0
Attacker Value
Unknown
CVE-2002-0567
Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
0
Attacker Value
Unknown
CVE-2001-0831
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.
0
Attacker Value
Unknown
CVE-2001-0941
Disclosure Date: November 30, 2001 (last updated February 22, 2025)
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.
0
Attacker Value
Unknown
CVE-2001-1041
Disclosure Date: August 31, 2001 (last updated February 22, 2025)
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
0