CVE-2004-1338
- EPSS 0.3%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, the...
CVE-2004-1339
- EPSS 0.49%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.
CVE-2004-1363
- EPSS 27.66%
- Veröffentlicht 04.08.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
- EPSS 32.44%
- Veröffentlicht 04.08.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
CVE-2003-0727
- EPSS 85.76%
- Veröffentlicht 20.10.2003 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.
- EPSS 12.51%
- Veröffentlicht 12.05.2003 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
- EPSS 59.49%
- Veröffentlicht 03.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own a...
- EPSS 46.32%
- Veröffentlicht 03.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to th...
CVE-2002-1767
- EPSS 4.04%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.
CVE-2002-0840
- EPSS 90.18%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web pag...