Vulnerabilities > Oracle > Database Server > 10.2.0.3

DATE CVE VULNERABILITY TITLE RISK
2007-07-18 CVE-2007-3856 Unspecified vulnerability in Oracle Database Server and Oracle10G
Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2.0.2 and 10.2.0.3, 10g 10.1.0.5, and Oracle9i Database Release 2 9.2.0.7, 9.2.0.8, and 9.2.0.8DV has unknown impact and remote authenticated attack vectors related to DMSYS.DMP_SYS, aka DB04.
network
low complexity
oracle
6.5
2007-07-18 CVE-2007-3855 Unspecified vulnerability in Oracle Database Server
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17).
network
low complexity
oracle
6.5
2007-07-18 CVE-2007-3854 Unspecified vulnerability in Oracle products
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12).
network
low complexity
oracle
5.5
2007-07-18 CVE-2007-3853 Unspecified vulnerability in Oracle Database Server 10.1.0.5/10.2.0.3
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle Text component (DB09), and (3) MDSYS.SDO_GEOR_INT in the Spatial component (DB15).
network
low complexity
oracle
6.5
2007-04-18 CVE-2007-2112 Multiple vulnerability in Oracle Database Server 10.1.0.5/10.2.0.3
Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05.
network
oracle
6.0
2007-04-18 CVE-2007-2109 Multiple vulnerability in Oracle Database Server 10.2.0.3
Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (2) Oracle Streams (DB06).
network
oracle
6.0
2007-01-17 CVE-2007-0275 Cross-Site Scripting vulnerability in Oracle products
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.
network
oracle CWE-79
3.5
2007-01-17 CVE-2007-0273 Multiple vulnerability in Oracle January 2007 Security Update
Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.
network
oracle
4.3
2007-01-17 CVE-2007-0269 Multiple vulnerability in Oracle Database Server 10.1.0.5/10.2.0.3/9.2.0.8
Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.
network
low complexity
oracle
5.5