CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9793 | CVE-2004-1365 | Candidate | Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9794 | CVE-2004-1366 | Candidate | Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9795 | CVE-2004-1367 | Candidate | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9796 | CVE-2004-1368 | Candidate | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | Assigned (20050107) | None (candidate not yet proposed) | View | |
9797 | CVE-2004-1369 | Candidate | The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory. | Assigned (20050107) | None (candidate not yet proposed) | View |
Page 19886 of 20943, showing 5 records out of 104715 total, starting on record 99426, ending on 99430