Vulnerability index

Browse CVEs

6,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Application Server Portal HIGH 7.5
CVE-2003-1193

Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracl…

Patch available
Fix from $1,950 2003-11-03
Applications HIGH 7.5
CVE-2003-0632

Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.…

Mitigation only
Fix from $1,950 2003-08-27
Oracle8i HIGH 7.5
CVE-2003-0634EPSS 7%

Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database u…

Patch available
Fix from $1,950 2003-08-27
Applications MEDIUM 5.0
CVE-2003-0633

Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remot…

Mitigation only
Fix from $1,600 2003-08-27
Sun One Application Server HIGH 7.5
CVE-2003-0411EPSS 25%

Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" ext…

Patch available
Fix from $1,950 2003-06-30
Database Server HIGH 9.0
CVE-2003-0222EPSS 11%

Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…

Patch available
Fix from $1,950 2003-05-12
MySQL HIGH 9.0
CVE-2003-0150EPSS 45%

MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator …

Patch available
Fix from $1,950 2003-03-24
Database Server HIGH 10.0
CVE-2003-0095EPSS 13%

Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…

Patch available
Fix from $1,950 2003-03-03
Database Server HIGH 9.0
CVE-2003-0096EPSS 16%

Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…

Mitigation only
Fix from $1,950 2003-03-03
Application Server HIGH 7.5
CVE-2002-0842EPSS 15%

Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2)…

Patch available
Fix from $1,950 2003-03-03
MySQL MEDIUM 5.0
CVE-2003-0073

Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change…

Patch available
Fix from $1,600 2003-02-19
Application Server HIGH 7.5
CVE-2002-1630EPSS 7%

The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails.

Patch available
Fix from $1,950 2002-12-31
Application Server HIGH 7.5
CVE-2002-1631EPSS 8%

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code vi…

Patch available
Fix from $1,950 2002-12-31
MySQL HIGH 7.5
CVE-2002-1809EPSS 16%

The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers …

No fix yet
Fix from $1,950 2002-12-31
E Business Suite HIGH 7.5
CVE-2002-1882EPSS 5%

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authenticat…

Patch available
Fix from $1,950 2002-12-31
MySQL HIGH 7.5
CVE-2002-1921

The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allow…

Mitigation only
Fix from $1,950 2002-12-31
MySQL HIGH 7.5
CVE-2002-1923

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attacker…

Mitigation only
Fix from $1,950 2002-12-31
Application Server HIGH 7.5
CVE-2002-2153EPSS 7%

Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers …

Mitigation only
Fix from $1,950 2002-12-31
Application Server HIGH 7.5
CVE-2002-2345

Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.

Mitigation only
Fix from $1,950 2002-12-31
Database Server HIGH 7.2
CVE-2002-1767

Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long co…

No fix yet
Fix from $1,950 2002-12-31
Application Server MEDIUM 6.4
CVE-2002-1632EPSS 5%

Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive in…

Patch available
Fix from $1,600 2002-12-31
Application Server MEDIUM 5.0
CVE-2002-1635

The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias,…

Mitigation only
Fix from $1,600 2002-12-31
E Business Suite MEDIUM 5.0
CVE-2002-1666

Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying t…

Patch available
Fix from $1,600 2002-12-31
Application Server MEDIUM 5.0
CVE-2002-1858

Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB…

Patch available
Fix from $1,600 2002-12-31
MySQL HIGH 7.5
CVE-2002-1374EPSS 20%

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack us…

Patch available
Fix from $1,950 2002-12-23
MySQL HIGH 7.5
CVE-2002-1375EPSS 24%

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.

Patch available
Fix from $1,950 2002-12-23
MySQL HIGH 7.5
CVE-2002-1376EPSS 7%

libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read…

Patch available
Fix from $1,950 2002-12-23
MySQL MEDIUM 5.0
CVE-2002-1373

Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (cras…

Patch available
Fix from $1,600 2002-12-23
Oracle9i HIGH 7.5
CVE-2002-1264EPSS 8%

Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USER…

Mitigation only
Fix from $1,950 2002-11-12
Application Server MEDIUM 5.0
CVE-2002-0386EPSS 22%

The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash…

Patch available
Fix from $1,600 2002-11-04