Vulnerability index

Browse CVEs

6,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Oracle8i MEDIUM 5.0
CVE-2002-1118

TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or…

Patch available
Fix from $1,600 2002-10-28
MySQL HIGH 7.8
CVE-2002-0969

Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary cod…

Fix: 3.23.50+
Fix from $1,950 2002-10-11
Application Server HIGH 7.5
CVE-2002-0947EPSS 10%

Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote atta…

Patch available
Fix from $1,950 2002-10-04
Oracle9i HIGH 7.5
CVE-2002-0965EPSS 70%

Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code vi…

Patch available
Fix from $1,950 2002-10-04
Application Server MEDIUM 5.0
CVE-2002-1089EPSS 5%

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attacker…

Mitigation only
Fix from $1,600 2002-10-04
Database Server HIGH 7.5
CVE-2002-0857EPSS 14%

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute …

Patch available
Fix from $1,950 2002-09-05
Oracle8i HIGH 7.5
CVE-2002-0858

catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database ope…

Mitigation only
Fix from $1,950 2002-09-05
Database Server MEDIUM 5.0
CVE-2002-0856

SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that a…

Patch available
Fix from $1,600 2002-09-05
Oracle9i MEDIUM 5.0
CVE-2002-0509

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single…

Mitigation only
Fix from $1,600 2002-08-12
Application Server HIGH 7.5
CVE-2002-0559EPSS 13%

Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute ar…

Patch available
Fix from $1,950 2002-07-03
Application Server HIGH 7.5
CVE-2002-0561EPSS 10%

The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which …

Patch available
Fix from $1,950 2002-07-03
Application Server HIGH 7.5
CVE-2002-0564EPSS 5%

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DA…

Patch available
Fix from $1,950 2002-07-03
Database Server HIGH 7.5
CVE-2002-0567EPSS 9%

Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functio…

Patch available
Fix from $1,950 2002-07-03
Application Server HIGH 7.5
CVE-2002-0569EPSS 19%

Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (…

Patch available
Fix from $1,950 2002-07-03
Oracle9i HIGH 7.5
CVE-2002-0571

Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.

Patch available
Fix from $1,950 2002-07-03
Application Server MEDIUM 5.0
CVE-2002-0560

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored proce…

Patch available
Fix from $1,600 2002-07-03
Application Server MEDIUM 5.0
CVE-2002-0562EPSS 7%

The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows re…

Patch available
Fix from $1,600 2002-07-03
Application Server MEDIUM 5.0
CVE-2002-0563EPSS 51%

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, …

Patch available
Fix from $1,600 2002-07-03
Application Server MEDIUM 5.0
CVE-2002-0565EPSS 6%

Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to o…

Patch available
Fix from $1,600 2002-07-03
Application Server MEDIUM 5.0
CVE-2002-0566

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorizatio…

Patch available
Fix from $1,600 2002-07-03
Application Server Web Cache HIGH 10.0
CVE-2002-1641EPSS 9%

Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown ve…

Mitigation only
Fix from $1,950 2002-05-27
Configurator HIGH 7.5
CVE-2002-1639EPSS 5%

Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.…

Fix: after 11.5.7.17.31
Fix from $1,950 2002-04-01
Configurator MEDIUM 6.8
CVE-2002-1640EPSS 5%

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arb…

Fix: after 11.5.7.17.31
Fix from $1,600 2002-04-01
Application Server Web Cache MEDIUM 5.0
CVE-2002-0102

Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a la…

Patch available
Fix from $1,600 2002-03-25
Application Server HIGH 7.5
CVE-2001-1371EPSS 12%

The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn…

Patch available
Fix from $1,950 2002-02-06
Application Server MEDIUM 5.0
CVE-2001-1372EPSS 6%

Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existe…

Patch available
Fix from $1,600 2002-02-06
Application Server HIGH 7.5
CVE-2001-1216EPSS 9%

Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a he…

Patch available
Fix from $1,950 2001-12-21
Application Server MEDIUM 5.0
CVE-2001-1217EPSS 54%

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive informat…

Patch available
Fix from $1,600 2001-12-21
Application Server Web Cache HIGH 7.5
CVE-2001-0836EPSS 15%

Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

Mitigation only
Fix from $1,950 2001-12-06
Database Server HIGH 7.2
CVE-2001-0833

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, ak…

Fix: after 9.0.1
Fix from $1,950 2001-12-06