Vulnerability index

Browse CVEs

2,358 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Application Server MEDIUM 6.8
CVE-2007-2119

Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Datab…

Mitigation only
Fix from $1,600 2007-04-18
Database Server MEDIUM 6.0
CVE-2007-2109

Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Man…

Mitigation only
Fix from $1,600 2007-04-18
Database Server MEDIUM 6.0
CVE-2007-2112

Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05. …

Mitigation only
Fix from $1,600 2007-04-18
Database Server HIGH 7.2
CVE-2007-1442

Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DAC…

No fix yet
Fix from $1,950 2007-03-14
Database Server MEDIUM 6.0
CVE-2006-7141EPSS 6%

Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" pri…

No fix yet
Fix from $1,600 2007-03-07
Database Server MEDIUM 6.0
CVE-2006-7067EPSS 7%

Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session …

No fix yet
Fix from $1,600 2007-03-02
Solaris HIGH 10.0
CVE-2007-0882EPSS 98%

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" seque…

No fix yet
Fix from $1,950 2007-02-12
Oracle10g MEDIUM 6.8
CVE-2006-6703

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc para…

Mitigation only
Fix from $1,600 2006-12-23
Application Server Portal MEDIUM 5.0
CVE-2006-6699

Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers an…

Mitigation only
Fix from $1,600 2006-12-23
Application Server Portal HIGH 7.5
CVE-2006-6697EPSS 11%

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrar…

Mitigation only
Fix from $1,950 2006-12-22
Database Server HIGH 9.0
CVE-2006-1873

Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial compo…

No fix yet
Fix from $1,950 2006-04-20
Database Server HIGH 7.5
CVE-2006-1872

Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intell…

No fix yet
Fix from $1,950 2006-04-20
Database Server HIGH 7.5
CVE-2006-1874

Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial compone…

No fix yet
Fix from $1,950 2006-04-20
Diagnostics HIGH 7.5
CVE-2006-1035

Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vec…

No fix yet
Fix from $1,950 2006-03-07
Diagnostics HIGH 7.5
CVE-2006-1037

SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown at…

Mitigation only
Fix from $1,950 2006-03-07
Application Server HIGH 7.5
CVE-2006-0586EPSS 7%

Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multi…

Mitigation only
Fix from $1,950 2006-02-08
Database Server HIGH 7.5
CVE-2006-0547EPSS 10%

Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit …

Mitigation only
Fix from $1,950 2006-02-04
Database Server HIGH 7.5
CVE-2006-0548

SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execu…

Mitigation only
Fix from $1,950 2006-02-04
Database Server HIGH 7.5
CVE-2006-0549EPSS 8%

SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers…

Mitigation only
Fix from $1,950 2006-02-04
Database Server HIGH 10.0
CVE-2006-0256EPSS 5%

Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and …

No fix yet
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0258EPSS 6%

Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors…

No fix yet
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0261EPSS 6%

Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as…

Mitigation only
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0262

Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…

Mitigation only
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0263EPSS 7%

Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impac…

Mitigation only
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0270

Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and att…

Mitigation only
Fix from $1,950 2006-01-18
Database Server HIGH 10.0
CVE-2006-0271

Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…

Mitigation only
Fix from $1,950 2006-01-18
Application Server HIGH 10.0
CVE-2006-0273EPSS 5%

Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as ide…

No fix yet
Fix from $1,950 2006-01-18
Application Server HIGH 10.0
CVE-2006-0274EPSS 6%

Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and at…

No fix yet
Fix from $1,950 2006-01-18
E Business Suite HIGH 10.0
CVE-2006-0277

Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by…

No fix yet
Fix from $1,950 2006-01-18
E Business Suite HIGH 10.0
CVE-2006-0278

Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by …

No fix yet
Fix from $1,950 2006-01-18