CVE-2002-0857
- EPSS 13.79%
- Veröffentlicht 05.09.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:16
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listene...
CVE-2002-0567
- EPSS 8.74%
- Veröffentlicht 03.07.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:57:41
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
CVE-2001-0831
- EPSS 0.56%
- Veröffentlicht 06.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:02
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.
CVE-2001-0832
- EPSS 0.49%
- Veröffentlicht 06.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:03
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in ...
CVE-2001-0833
- EPSS 2.15%
- Veröffentlicht 06.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:03
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
CVE-2001-0941
- EPSS 1.66%
- Veröffentlicht 30.11.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:16
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.
CVE-2001-0942
- EPSS 0.56%
- Veröffentlicht 29.11.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:16
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious ...
CVE-2001-0943
- EPSS 1.97%
- Veröffentlicht 31.08.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:16
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Hors...
CVE-2001-1041
- EPSS 0.58%
- Veröffentlicht 31.08.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:55:28
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
- EPSS 2.08%
- Veröffentlicht 21.07.2001 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:54:26
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.