Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2012-08-17 CVE-2009-5026 SQL Injection vulnerability in multiple products
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
network
mysql oracle CWE-89
6.8
2012-08-10 CVE-2012-3132 SQL Injection vulnerability in Oracle Database Server
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
network
low complexity
oracle CWE-89
6.5
2012-07-17 CVE-2012-3135 Unspecified vulnerability in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
network
low complexity
oracle
critical
10.0
2012-07-17 CVE-2012-3134 Remote Core RDBMS vulnerability in Oracle Database Server 11.1.0.7/11.2.0.2/11.2.0.3
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect availability via unknown vectors.
network
low complexity
oracle
4.0
2012-07-17 CVE-2012-3128 Local SPARC T-Series Servers vulnerability in Oracle Sun Products Suite
Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager.
local
high complexity
oracle
3.7
2012-07-17 CVE-2012-3126 Local Solaris Cluster vulnerability in Oracle SUN products Suite 3.3
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.
local
high complexity
oracle
6.2
2012-07-17 CVE-2012-3119 Unspecified vulnerability in Oracle Peoplesoft products 9.0.20
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0.20 allows remote authenticated users to affect confidentiality via unknown vectors related to Candidate Gateway.
network
low complexity
oracle
4.0
2012-07-17 CVE-2012-3118 Unspecified vulnerability in Oracle Peoplesoft products 8.52
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect confidentiality, related to PANPROC.
network
low complexity
oracle
4.0
2012-07-17 CVE-2012-3117 Unspecified vulnerability in Oracle Supply Chain products Suite
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to HTTP.
network
low complexity
oracle
4.0
2012-07-17 CVE-2012-3116 Unspecified vulnerability in Oracle Supply Chain products Suite
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows local users to affect confidentiality via unknown vectors.
local
oracle
1.9