CVE-2007-6260
- EPSS 0.87%
- Published 06.12.2007 02:46:00
- Last modified 09.04.2025 00:30:58
The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configura...
CVE-2007-5897
- EPSS 3.22%
- Published 08.11.2007 21:46:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via the TRANSFORM function. NOTE: th...
- EPSS 48.15%
- Published 08.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument.
CVE-2007-5554
- EPSS 0.17%
- Published 18.10.2007 20:17:00
- Last modified 09.04.2025 00:30:58
Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a w...
CVE-2007-5504
- EPSS 3.42%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+ and 10.1.0.5 unknown impact and remote attack vectors, related to (1) Import (DB01) and (2) Advanced Queuing (DB25). NOTE: as of 20071108, Oracle has not disputed reliable researcher c...
CVE-2007-5505
- EPSS 0.71%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to (1) the Export component (DB02), (2) Oracle Text (DB04), (3) Oracle Text (DB05), (4...
CVE-2007-5506
- EPSS 6.22%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (CPU consumption) via a crafted type 6 Data packet, aka DB20.
CVE-2007-5507
- EPSS 5.86%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a conn...
CVE-2007-5508
- EPSS 1.4%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GI...
CVE-2007-5509
- EPSS 0.54%
- Published 17.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06.