Oracle

Database Server

515 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.47%
  • Published 07.03.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepath...

Exploit
  • EPSS 1.58%
  • Published 02.03.2007 21:18:00
  • Last modified 09.04.2025 00:30:58

Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third part...

Exploit
  • EPSS 6.62%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys...

  • EPSS 0.79%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.

  • EPSS 18.6%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.

  • EPSS 9.73%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this ...

  • EPSS 33.96%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedu...

  • EPSS 0.73%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for mu...

Exploit
  • EPSS 18.17%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09). NO...

  • EPSS 1.04%
  • Published 17.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Su...