Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2011-01-19 CVE-2010-3587 Common Applications Component Remote vulnerability in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Common Applications component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to User Management.
network
oracle
4.3
2011-01-19 CVE-2010-3510 Remote Security vulnerability in Oracle WebLogic Server
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Node Manager.
network
low complexity
oracle
critical
10.0
2011-01-19 CVE-2010-3505 Remote Security vulnerability in Oracle Supply Chain products Suite 9.3.0.2/9.3.1
Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders, Files & Attachments, a different vulnerability than CVE-2010-4429.
network
oracle
3.5
2011-01-14 CVE-2010-3840 Denial Of Service vulnerability in Oracle MySQL Prior to 5.1.51
The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.
network
low complexity
mysql oracle
4.0
2011-01-14 CVE-2010-3839 Denial Of Service vulnerability in Oracle MySQL Prior to 5.1.51
MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (infinite loop) via multiple invocations of a (1) prepared statement or (2) stored procedure that creates a query with nested JOIN statements.
network
low complexity
mysql oracle
4.0
2011-01-14 CVE-2010-3838 Denial Of Service vulnerability in Oracle MySQL Prior to 5.1.51
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary table."
network
low complexity
mysql oracle
4.0
2011-01-14 CVE-2010-3837 Resource Management Errors vulnerability in multiple products
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a prepared statement that uses GROUP_CONCAT with the WITH ROLLUP modifier, probably triggering a use-after-free error when a copied object is modified in a way that also affects the original object.
network
low complexity
mysql oracle CWE-399
4.0
2011-01-14 CVE-2010-3836 Resource Management Errors vulnerability in multiple products
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimizers.
network
low complexity
mysql oracle CWE-399
4.0
2011-01-14 CVE-2010-3835 Numeric Errors vulnerability in multiple products
MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expression to be re-evaluated instead of accessing its value from the table.
network
low complexity
mysql oracle CWE-189
4.0
2011-01-14 CVE-2010-3834 Denial Of Service vulnerability in Oracle MySQL Prior to 5.1.51
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
network
low complexity
mysql oracle
4.0