CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3316 | CVE-2001-0499 | Candidate | Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. | Modified (20050509) | ACCEPT(3) Armstrong, Cole, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Frech> XF:oracle-tns-listener-bo(6758) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | Christey> CERT:CA-2001-16 | URL:http://www.cert.org/advisories/CA-2001-16.html | CIAC:L-108 | URL:http://ciac.llnl.gov/ciac/bulletins/l-108.shtml | CERT-VN:VU#620495 | URL:http://www.kb.cert.org/vuls/id/620495 | BID:2941 | URL:http://www.securityfocus.com/bid/2941 | Christey> Consider adding BID:2941 | Christey> BUGTRAQ:20021126 Oracle TNS SEH Exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103833206805744&w=2 | Christey> CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | View |
5476 | CVE-2002-1089 | Candidate | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. | Modified (20050610) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:oracle-reports-information-disclosure(9628) | View |
3329 | CVE-2001-0515 | Candidate | Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. | Modified (20020223-01) | ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf | View |
3315 | CVE-2001-0498 | Candidate | Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension. | Proposed (20010727) | ACCEPT(5) Armstrong, Cole, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf | CVE-2001-0498 possible dupe of CVE-2001-0515, which is already | assigned to oracle-listener-offsettodata-dos(6713) | Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue. Oracle patch site is restricted, but taking NAI"s word as verification. | Christey> Consider adding BID:2940 | View |
3330 | CVE-2001-0516 | Candidate | Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data. | Modified (20020223-01) | ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:oracle-listener-incorrect-version-dos(6714) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf | View |
Page 113 of 20943, showing 5 records out of 104715 total, starting on record 561, ending on 565