Vulnerabilities > Oracle > Database Server > High

DATE CVE VULNERABILITY TITLE RISK
2006-02-04 CVE-2006-0547 SQL-Injection vulnerability in Oracle10g Personal Edition
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol.
network
low complexity
oracle
7.5
2005-11-16 CVE-2005-3641 Authentication Bypass vulnerability in Oracle Database Windows XP Simple File Sharing
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
network
low complexity
oracle
7.5
2005-05-02 CVE-2005-1197 SQL-Injection vulnerability in Oracle10g Enterprise Edition
SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.
network
low complexity
oracle
7.5
2005-01-18 CVE-2005-0297 Unspecified vulnerability in Oracle Database Server 10.2.1
SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.
network
low complexity
oracle
7.5
2002-12-31 CVE-2002-1767 Local Command Parameter Buffer Overflow vulnerability in Oracle Database Server 8.1.5
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.
local
low complexity
oracle
7.2
2002-09-05 CVE-2002-0857 Unspecified vulnerability in Oracle Database Server and Oracle8I
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
network
low complexity
oracle
7.5
2002-07-03 CVE-2002-0567 Unspecified vulnerability in Oracle Database Server, Oracle8I and Oracle9I
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
network
low complexity
oracle
7.5
2001-12-06 CVE-2001-0833 Buffer Overflow vulnerability in Oracle OTRCREP Oracle Home Environment Variable
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
local
low complexity
oracle
7.2
2001-08-31 CVE-2001-0943 Unspecified vulnerability in Oracle Database Server 8.0.5/8.1.5
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
local
low complexity
oracle
7.2