NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71750 | CVE-2004-1371 | Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure. | 2 | 9 | High | 2017-07-18 | 2017-07-10 | View | |
71749 | CVE-2004-1370 | Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71748 | CVE-2004-1369 | The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71747 | CVE-2004-1368 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | 2 | 7.8 | High | 2017-07-18 | 2017-07-10 | View | |
71746 | CVE-2004-1367 | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password. | 2 | 4.4 | Medium | 2016-12-20 | 2016-10-17 | View |
Page 15771 of 17672, showing 5 records out of 88360 total, starting on record 78851, ending on 78855