CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3316  CVE-2001-0499  Candidate  Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.  Modified (20050509)  ACCEPT(3) Armstrong, Cole, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-tns-listener-bo(6758) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | Christey> CERT:CA-2001-16 | URL:http://www.cert.org/advisories/CA-2001-16.html | CIAC:L-108 | URL:http://ciac.llnl.gov/ciac/bulletins/l-108.shtml | CERT-VN:VU#620495 | URL:http://www.kb.cert.org/vuls/id/620495 | BID:2941 | URL:http://www.securityfocus.com/bid/2941 | Christey> Consider adding BID:2941 | Christey> BUGTRAQ:20021126 Oracle TNS SEH Exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103833206805744&w=2 | Christey> CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf  View
5476  CVE-2002-1089  Candidate  rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:oracle-reports-information-disclosure(9628)  View
3329  CVE-2001-0515  Candidate  Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.  Modified (20020223-01)  ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf  View
3315  CVE-2001-0498  Candidate  Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.  Proposed (20010727)  ACCEPT(5) Armstrong, Cole, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf | CVE-2001-0498 possible dupe of CVE-2001-0515, which is already | assigned to oracle-listener-offsettodata-dos(6713) | Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue. Oracle patch site is restricted, but taking NAI"s word as verification. | Christey> Consider adding BID:2940  View
3330  CVE-2001-0516  Candidate  Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.  Modified (20020223-01)  ACCEPT(4) Armstrong, Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:oracle-listener-incorrect-version-dos(6714) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf  View

Page 113 of 20943, showing 5 records out of 104715 total, starting on record 561, ending on 565

Actions