Vulnerability index

Browse CVEs

6,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Database Server HIGH 7.2
CVE-2001-0943

dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp comma…

Patch available
Fix from $1,950 2001-08-31
Application Server HIGH 7.5
CVE-2001-0591

Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute…

Fix: after 1.1.1
Fix from $1,950 2001-08-22
E Business Suite HIGH 7.2
CVE-2001-0528

Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS …

Patch available
Fix from $1,950 2001-08-14
Oracle8i HIGH 10.0
CVE-2001-0499EPSS 85%

Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long …

Fix: after 8.1.7
Fix from $1,950 2001-07-21
Oracle8i MEDIUM 5.0
CVE-2001-0498

Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malf…

Fix: after 8.1.7
Fix from $1,600 2001-07-21
Oracle9i MEDIUM 5.0
CVE-2001-0513

Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allow…

Patch available
Fix from $1,600 2001-07-21
Database Server MEDIUM 5.0
CVE-2001-0515

Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_da…

Fix: after 8.1.7
Fix from $1,600 2001-07-21
Oracle8i MEDIUM 5.0
CVE-2001-0516

Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains…

Patch available
Fix from $1,600 2001-07-21
Oracle8i MEDIUM 5.0
CVE-2001-0517

Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transpo…

Patch available
Fix from $1,600 2001-07-21
Oracle9i MEDIUM 5.0
CVE-2001-0518

Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command…

Patch available
Fix from $1,600 2001-07-21
Internet Directory HIGH 7.5
CVE-2001-0974EPSS 6%

Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demon…

Patch available
Fix from $1,950 2001-07-17
Internet Directory HIGH 7.5
CVE-2001-0975EPSS 9%

Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as dem…

Patch available
Fix from $1,950 2001-07-16
Internet Directory HIGH 7.5
CVE-2001-1321EPSS 6%

Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code v…

Patch available
Fix from $1,950 2001-07-16
Application Server HIGH 7.5
CVE-2001-0419EPSS 24%

Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allo…

No fix yet
Fix from $1,950 2001-07-02
Application Server HIGH 7.5
CVE-2001-0326EPSS 5%

Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary fi…

Patch available
Fix from $1,950 2001-05-03
Oracle8i HIGH 7.5
CVE-2001-0126

Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via t…

Mitigation only
Fix from $1,950 2001-03-12
Database Server MEDIUM 5.0
CVE-1999-0784

Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.

No fix yet
Fix from $1,600 2001-03-12
MySQL HIGH 7.5
CVE-2001-1453EPSS 11%

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

No fix yet
Fix from $1,950 2001-02-09
MySQL HIGH 7.5
CVE-2001-1454EPSS 10%

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

Fix: after 3.23.32
Fix from $1,950 2001-02-09
MySQL HIGH 7.5
CVE-2001-1274EPSS 5%

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

Fix: after 3.23.31
Fix from $1,950 2001-01-23
MySQL HIGH 7.2
CVE-2001-1275

MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.u…

Fix: after 3.23.31
Fix from $1,950 2001-01-19
Application Server HIGH 7.5
CVE-2000-1236

SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL…

Fix: after 3.0.7
Fix from $1,950 2000-12-31
Application Server MEDIUM 5.0
CVE-2000-1235

The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attac…

Fix: after 3.0.7
Fix from $1,600 2000-12-31
Listener HIGH 10.0
CVE-2000-0818

The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to ar…

Patch available
Fix from $1,950 2000-12-19
MySQL HIGH 7.2
CVE-2000-0981

MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.

Mitigation only
Fix from $1,950 2000-12-19
Web Listener MEDIUM 5.0
CVE-2000-0576

Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.

No fix yet
Fix from $1,600 2000-07-05
Application Server HIGH 7.5
CVE-2000-0169EPSS 27%

Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.

Mitigation only
Fix from $1,950 2000-03-15
Oracle8i MEDIUM 6.2
CVE-2000-0206

The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local…

Mitigation only
Fix from $1,600 2000-03-05
MySQL HIGH 7.5
CVE-2000-0148

MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.

Mitigation only
Fix from $1,950 2000-02-08
MySQL MEDIUM 6.4
CVE-2000-0045EPSS 7%

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

Mitigation only
Fix from $1,600 2000-01-11