Vulnerability index

Browse CVEs

2,358 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

10g Enterprise Manager Database Control HIGH 10.0
CVE-2005-3460

Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by…

No fix yet
Fix from $1,950 2005-11-02
Database Server HIGH 10.0
CVE-2005-3437EPSS 5%

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln#…

No fix yet
Fix from $1,950 2005-11-02
Database Server HIGH 10.0
CVE-2005-3440EPSS 5%

Unspecified vulnerability in Database Scheduler in Oracle Database Server 10g up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# …

No fix yet
Fix from $1,950 2005-11-02
Database Server HIGH 10.0
CVE-2005-3443

Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle…

No fix yet
Fix from $1,950 2005-11-02
Database Server HIGH 10.0
CVE-2005-3444EPSS 5%

Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vec…

No fix yet
Fix from $1,950 2005-11-02
Html Db MEDIUM 6.8
CVE-2005-3202EPSS 11%

Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web scrip…

No fix yet
Fix from $1,600 2005-10-14
Reports HIGH 7.5
CVE-2005-2983

SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in…

No fix yet
Fix from $1,950 2005-09-20
MySQL HIGH 8.5
CVE-2005-2572

MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server…

Mitigation only
Fix from $1,950 2005-08-16
Forms HIGH 7.2
CVE-2005-2372

Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attacker…

No fix yet
Fix from $1,950 2005-07-26
Reports MEDIUM 5.0
CVE-2005-2371EPSS 22%

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windo…

Mitigation only
Fix from $1,600 2005-07-26
Reports MEDIUM 5.0
CVE-2005-2378EPSS 9%

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTO…

No fix yet
Fix from $1,600 2005-07-26
Application Server HIGH 7.5
CVE-2005-1495

Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier f…

No fix yet
Fix from $1,950 2005-05-11
Application Server Web Cache MEDIUM 6.8
CVE-2005-1381EPSS 20%

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) c…

No fix yet
Fix from $1,600 2005-05-03
Application Server Web Cache MEDIUM 5.0
CVE-2005-1382EPSS 7%

The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file paramete…

No fix yet
Fix from $1,600 2005-05-03
Forms HIGH 7.5
CVE-2005-1178

SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.

Mitigation only
Fix from $1,950 2005-05-02
MySQL MEDIUM 5.0
CVE-2005-0799

MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a us…

No fix yet
Fix from $1,600 2005-03-15
MySQL MEDIUM 6.8
CVE-2004-0957

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants pr…

Mitigation only
Fix from $1,600 2005-02-09
Database Server HIGH 7.5
CVE-2005-0297

SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

Mitigation only
Fix from $1,950 2005-01-18
HTTP Server MEDIUM 6.8
CVE-2004-2115EPSS 58%

Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script…

No fix yet
Fix from $1,600 2004-12-31
Peopletools MEDIUM 5.0
CVE-2003-0841

The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to…

Mitigation only
Fix from $1,600 2003-11-17
Applications HIGH 7.5
CVE-2003-0632

Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.…

Mitigation only
Fix from $1,950 2003-08-27
Applications MEDIUM 5.0
CVE-2003-0633

Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remot…

Mitigation only
Fix from $1,600 2003-08-27
Database Server HIGH 9.0
CVE-2003-0096EPSS 16%

Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…

Mitigation only
Fix from $1,950 2003-03-03
MySQL HIGH 7.5
CVE-2002-1809EPSS 16%

The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers …

No fix yet
Fix from $1,950 2002-12-31
MySQL HIGH 7.5
CVE-2002-1921

The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allow…

Mitigation only
Fix from $1,950 2002-12-31
MySQL HIGH 7.5
CVE-2002-1923

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attacker…

Mitigation only
Fix from $1,950 2002-12-31
Application Server HIGH 7.5
CVE-2002-2153EPSS 7%

Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers …

Mitigation only
Fix from $1,950 2002-12-31
Application Server HIGH 7.5
CVE-2002-2345

Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.

Mitigation only
Fix from $1,950 2002-12-31
Database Server HIGH 7.2
CVE-2002-1767

Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long co…

No fix yet
Fix from $1,950 2002-12-31
Application Server MEDIUM 5.0
CVE-2002-1635

The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias,…

Mitigation only
Fix from $1,600 2002-12-31