Vulnerabilities > Oracle > Database Server

DATE CVE VULNERABILITY TITLE RISK
2007-01-17 CVE-2007-0270 Buffer Errors vulnerability in Oracle Database Server 10.1.0.4/9.2.0.7
Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.
network
low complexity
oracle CWE-119
6.5
2007-01-17 CVE-2007-0269 Multiple vulnerability in Oracle Database Server 10.1.0.5/10.2.0.3/9.2.0.8
Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.
network
low complexity
oracle
5.5
2007-01-17 CVE-2007-0268 Multiple vulnerability in Oracle Database Server 10.1.0.5/9.0.1.5/9.2.0.7
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).
network
low complexity
oracle
6.5
2006-10-18 CVE-2006-5345 Multiple vulnerability in Oracle Database Server 10.1.0.4/9.0.1.5/9.2.0.7
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB22.
network
low complexity
oracle
critical
9.0
2006-10-18 CVE-2006-5344 Multiple vulnerability in Oracle October 2006 Security Update
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vuln# DB20, and (2) mdsys.sdo_cs, aka DB21.
network
low complexity
oracle
critical
9.0
2006-10-18 CVE-2006-5343 Multiple vulnerability in Oracle Database Server 10.1.0.3
Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.
network
low complexity
oracle
critical
9.0
2006-10-18 CVE-2006-5342 Multiple vulnerability in Oracle October 2006 Security Update
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_tune, aka Vuln# DB18.
network
high complexity
oracle
7.1
2006-10-18 CVE-2006-5341 Multiple vulnerability in Oracle Database Server 10.1.0.5/10.2.0.2/9.2.0.7
Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz.
network
low complexity
oracle
critical
9.0
2006-10-18 CVE-2006-5340 Multiple vulnerability in Oracle October 2006 Security Update
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17.
network
high complexity
oracle
7.1
2006-10-18 CVE-2006-5339 Multiple vulnerability in Oracle October 2006 Security Update
Unspecified vulnerability in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB11.
network
low complexity
oracle
critical
9.0