- EPSS 1.47%
- Published 07.03.2007 20:19:00
- Last modified 09.04.2025 00:30:58
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepath...
- EPSS 1.58%
- Published 02.03.2007 21:18:00
- Last modified 09.04.2025 00:30:58
Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third part...
CVE-2007-0268
- EPSS 6.62%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys...
CVE-2007-0269
- EPSS 0.79%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.
CVE-2007-0270
- EPSS 18.6%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.
CVE-2007-0271
- EPSS 9.73%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this ...
CVE-2007-0272
- EPSS 33.96%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedu...
CVE-2007-0273
- EPSS 0.73%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for mu...
CVE-2007-0274
- EPSS 18.17%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09). NO...
CVE-2007-0275
- EPSS 1.04%
- Published 17.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Su...