CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4952  CVE-2002-0561  Candidate  The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  Frech> XF:oracle-appserver-plsql-web-interface(8452)  View
4497  CVE-2002-0103  Candidate  An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.  Modified (20050706)  ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Frech  Frech> XF:oracle-appserver-webcached-privileges(7766) | XF:oracle-appserver-webcache-password(7768) | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
3845  CVE-2001-1041  Candidate  oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey  Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3638  CVE-2001-0832  Candidate  Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."  Proposed (20011122)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:oracle-binary-symlink(6940) | Christey> Possible dupe with CVE-2001-1041; need to review more closely.  View
5248  CVE-2002-0858  Candidate  catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges.  Modified (20071101)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:oracle-catsnmp-default-account(9932)  View

Page 20829 of 20943, showing 5 records out of 104715 total, starting on record 104141, ending on 104145

Actions