CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9766  CVE-2004-1338  Candidate  The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.  Assigned (20050106)  None (candidate not yet proposed)    View
9767  CVE-2004-1339  Candidate  SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.  Assigned (20050106)  None (candidate not yet proposed)    View
9768  CVE-2004-1340  Candidate  Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.  Assigned (20050106)  None (candidate not yet proposed)    View
9769  CVE-2004-1341  Candidate  Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.  Assigned (20050106)  None (candidate not yet proposed)    View
9770  CVE-2004-1342  Candidate  CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.  Assigned (20050106)  None (candidate not yet proposed)    View

Page 1050 of 20943, showing 5 records out of 104715 total, starting on record 5246, ending on 5250

Actions