Vulnerabilities > Oracle > Application Server > 9.0.2.3

DATE CVE VULNERABILITY TITLE RISK
2005-11-02 CVE-2005-3450 Multiple vulnerability in Oracle October Security Update
Unspecified vulnerability in the HTTP Server in Oracle Application Server 1.0 up to 9.0.2.3 has unknown impact and attack vectors, as identified by Oracle Vuln# AS04.
network
low complexity
oracle
critical
10.0
2005-11-02 CVE-2005-3449 Multiple vulnerability in Oracle October Security Update
Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.
network
low complexity
oracle
critical
10.0
2005-11-02 CVE-2005-3448 Multiple vulnerability in Oracle October Security Update
Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01.
network
low complexity
oracle
critical
10.0
2005-11-02 CVE-2005-3447 Multiple vulnerability in Oracle October Security Update
Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08.
network
low complexity
oracle
critical
10.0
2005-11-02 CVE-2005-3446 Multiple vulnerability in Oracle Application Server and Database Server
Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06.
network
low complexity
oracle
critical
10.0
2005-11-02 CVE-2005-3445 Multiple vulnerability in Oracle Application Server and Database Server
Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.
network
low complexity
oracle
critical
10.0
2005-10-14 CVE-2005-3204 Cross-Site Scripting vulnerability in Oracle Application Server and Oracle9I
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
network
oracle
4.3
2004-08-04 CVE-2004-1371 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Oracle products
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
network
low complexity
oracle CWE-119
critical
9.0
2004-08-04 CVE-2004-1370 Multiple Unspecified vulnerability in Oracle
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
network
low complexity
oracle
7.5
2004-08-04 CVE-2004-1369 Multiple Unspecified vulnerability in Oracle
The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.
network
low complexity
oracle
5.0