Oracle

Oracle9i

52 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Published 04.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.

  • EPSS 0.4%
  • Published 04.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.

  • EPSS 15.17%
  • Published 04.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

  • EPSS 4%
  • Published 04.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedu...

Exploit
  • EPSS 12.3%
  • Published 30.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root ...

  • EPSS 0.12%
  • Published 17.11.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.

  • EPSS 0.43%
  • Published 03.11.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary ...

  • EPSS 2.65%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.

  • EPSS 12.51%
  • Published 12.05.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.

  • EPSS 46.32%
  • Published 03.03.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to th...