CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9791 | CVE-2004-1363 | Candidate | Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9792 | CVE-2004-1364 | Candidate | Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOMEin directory. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9793 | CVE-2004-1365 | Candidate | Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9794 | CVE-2004-1366 | Candidate | Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9795 | CVE-2004-1367 | Candidate | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password. | Assigned (20050107) | None (candidate not yet proposed) | View |
Page 1055 of 20943, showing 5 records out of 104715 total, starting on record 5271, ending on 5275