Vulnerability index

Browse CVEs

6,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Database Server MEDIUM 5.0
CVE-2005-0298

The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read pri…

Patch available
Fix from $1,600 2005-05-02
MySQL MEDIUM 5.0
CVE-2005-0799

MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a us…

No fix yet
Fix from $1,600 2005-03-15
Database Server MEDIUM 5.0
CVE-2005-0701EPSS 18%

Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modif…

Patch available
Fix from $1,600 2005-03-07
MySQL MEDIUM 6.8
CVE-2004-0957

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants pr…

Mitigation only
Fix from $1,600 2005-02-09
Database Server HIGH 7.5
CVE-2005-0297

SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

Mitigation only
Fix from $1,950 2005-01-18
MySQL MEDIUM 5.0
CVE-2004-0956

MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote b…

Patch available
Fix from $1,600 2005-01-10
Oracle8i HIGH 8.5
CVE-2004-0638EPSS 7%

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, …

Patch available
Fix from $1,950 2004-12-31
HTTP Server MEDIUM 6.8
CVE-2004-2115EPSS 58%

Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script…

No fix yet
Fix from $1,600 2004-12-31
Database Server MEDIUM 6.5
CVE-2004-2345

Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users with the ability to invoke SQL …

Patch available
Fix from $1,600 2004-12-31
MySQL MEDIUM 5.0
CVE-2004-2149EPSS 6%

Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2004-12-31
Application Server MEDIUM 5.0
CVE-2004-2244

The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database …

Patch available
Fix from $1,600 2004-12-31
Database Server MEDIUM 6.5
CVE-2004-1338

The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or …

Patch available
Fix from $1,600 2004-12-23
Database Server MEDIUM 6.5
CVE-2004-1339

SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote at…

Patch available
Fix from $1,600 2004-12-23
Oracle9i HIGH 10.0
CVE-2003-1208EPSS 13%

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to…

Patch available
Fix from $1,950 2004-12-03
MySQL HIGH 10.0
CVE-2004-0836EPSS 10%

Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of…

Fix: 3.23.49 / 4.0.21+
Fix from $1,950 2004-11-03
Oracle8i MEDIUM 6.5
CVE-2004-0637EPSS 18%

Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, whic…

Patch available
Fix from $1,600 2004-09-02
Application Server HIGH 7.2
CVE-2004-1774

Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users …

Patch available
Fix from $1,950 2004-08-31
Applications HIGH 10.0
CVE-2004-0543EPSS 7%

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execut…

Patch available
Fix from $1,950 2004-08-06
Application Server CRITICAL 9.8
CVE-2004-1363EPSS 9%

Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are e…

Patch available
Fix from $2,300 2004-08-04
Application Server HIGH 9.0
CVE-2004-1371EPSS 11%

Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…

Patch available
Fix from $1,950 2004-08-04
Application Server HIGH 8.5
CVE-2004-1364EPSS 14%

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\b…

Patch available
Fix from $1,950 2004-08-04
Application Server HIGH 7.8
CVE-2004-1368EPSS 6%

ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the l…

Patch available
Fix from $1,950 2004-08-04
Application Server HIGH 7.5
CVE-2004-1362EPSS 9%

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character …

Patch available
Fix from $1,950 2004-08-04
Application Server HIGH 7.5
CVE-2004-1370

Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbit…

Patch available
Fix from $1,950 2004-08-04
Application Server MEDIUM 5.0
CVE-2004-1369EPSS 6%

The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request co…

Patch available
Fix from $1,600 2004-08-04
Application Server HIGH 7.2
CVE-2004-1707

The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute librar…

Patch available
Fix from $1,950 2004-07-30
Application Server Web Cache HIGH 10.0
CVE-2004-0385EPSS 16%

Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execut…

Patch available
Fix from $1,950 2004-06-01
Jre HIGH 7.5
CVE-2003-1229

X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JR…

Fix: after 1.4.1
Fix from $1,950 2003-12-31
E Business Suite MEDIUM 5.0
CVE-2003-1116

The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1…

Patch available
Fix from $1,600 2003-12-31
Peopletools MEDIUM 5.0
CVE-2003-0841

The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to…

Mitigation only
Fix from $1,600 2003-11-17