CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3636  CVE-2001-0830  Entry  6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.        View
3637  CVE-2001-0831  Candidate  Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.  Modified (20050703)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:oracle-label-security-access(7344)  View
3638  CVE-2001-0832  Candidate  Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."  Proposed (20011122)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:oracle-binary-symlink(6940) | Christey> Possible dupe with CVE-2001-1041; need to review more closely.  View
3639  CVE-2001-0833  Entry  Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."        View
3640  CVE-2001-0834  Entry  htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.        View

Page 728 of 20943, showing 5 records out of 104715 total, starting on record 3636, ending on 3640

Actions