Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Oracle8i
(Oracle)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 46 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2002-07-03 | CVE-2002-0567 | Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process. | Database_server, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0566 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0564 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0563 | The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0561 | The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0560 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2002-07-03 | CVE-2002-0559 | Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name. | Application_server, Application_server_web_cache, Oracle8i, Oracle9i | N/A | ||
2001-07-21 | CVE-2001-0517 | Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0. | Oracle8i | N/A | ||
2001-07-21 | CVE-2001-0516 | Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data. | Oracle8i, Oracle9i | N/A | ||
2001-07-21 | CVE-2001-0515 | Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. | Database_server, Oracle8i | N/A |