CVE-2005-2093
- EPSS 2.59%
- Published 05.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Len...
CVE-2005-1495
- EPSS 1.04%
- Published 11.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
CVE-2005-1496
- EPSS 5.21%
- Published 11.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
CVE-2005-1383
- EPSS 60.99%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.
- EPSS 0.85%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and mem...
CVE-2004-1774
- EPSS 7.66%
- Published 31.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.
CVE-2004-1362
- EPSS 4%
- Published 04.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedu...
CVE-2004-1363
- EPSS 27.66%
- Published 04.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
CVE-2004-1364
- EPSS 15.17%
- Published 04.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
CVE-2004-1365
- EPSS 0.4%
- Published 04.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.