CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6025  CVE-2002-1641  Candidate  Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.  Assigned (20050328)  None (candidate not yet proposed)    View
6024  CVE-2002-1640  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet.  Assigned (20050328)  None (candidate not yet proposed)    View
6023  CVE-2002-1639  Candidate  Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".  Assigned (20050328)  None (candidate not yet proposed)    View
6022  CVE-2002-1638  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-2153. Reason: This candidate is a duplicate of CVE-2002-2153. Notes: All CVE users should reference CVE-2002-2153 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050328)  None (candidate not yet proposed)    View
6021  CVE-2002-1637  Candidate  Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges.  Assigned (20050328)  None (candidate not yet proposed)    View

Page 19739 of 20943, showing 5 records out of 104715 total, starting on record 98691, ending on 98695

Actions