CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4952 | CVE-2002-0561 | Candidate | The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat | Frech> XF:oracle-appserver-plsql-web-interface(8452) | View |
4497 | CVE-2002-0103 | Candidate | An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml. | Modified (20050706) | ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Frech | Frech> XF:oracle-appserver-webcached-privileges(7766) | XF:oracle-appserver-webcache-password(7768) | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
3845 | CVE-2001-1041 | Candidate | oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey | Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
3638 | CVE-2001-0832 | Candidate | Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability." | Proposed (20011122) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:oracle-binary-symlink(6940) | Christey> Possible dupe with CVE-2001-1041; need to review more closely. | View |
5248 | CVE-2002-0858 | Candidate | catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:oracle-catsnmp-default-account(9932) | View |
Page 20829 of 20943, showing 5 records out of 104715 total, starting on record 104141, ending on 104145