Oracle Oracle8I vulnerabilities
44 known vulnerabilities affecting oracle/oracle8i.
Total CVEs
44
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM19LOW1
Vulnerabilities
Page 2 of 3
CVE-1999-0711P4MEDIUMCVSS 4.6PoCv8.0.3v8.0.4+3 more1999-04-29
CVE-1999-0711 [MEDIUM] CVE-1999-0711: The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl
The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.
nvd
CVE-2002-0857P4HIGHCVSS 7.5v8.12002-09-05
CVE-2002-0857 [HIGH] CVE-2002-0857: Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
nvd
CVE-2002-0559P3HIGHCVSS 7.5v8.1.7v8.1.7.12002-07-03
CVE-2002-0559 [HIGH] CVE-2002-0559: Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote att
Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a
nvd
CVE-2000-0206P4MEDIUMCVSS 6.2PoCv8.1.52000-03-05
CVE-2000-0206 [MEDIUM] CVE-2000-0206: The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file wit
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.
nvd
CVE-2004-1368P4HIGHCVSS 7.8venterprise_8.0.5_.0.0venterprise_8.0.6_.0.0+17 more2004-08-04
CVE-2004-1368 [HIGH] CVE-2004-1368: ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an
ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
nvd
CVE-2000-0987P4MEDIUMCVSS 4.6PoCv8.1.62000-12-19
CVE-2000-0987 [MEDIUM] CVE-2000-0987: Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
nvd
CVE-2002-0568P4LOWCVSS 2.1v8.1.7v8.1.7.12002-07-03
CVE-2002-0568 [LOW] CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
nvd
CVE-1999-0888P4MEDIUMCVSS 4.6PoCv8.0.3v8.0.4+3 more1999-08-16
CVE-1999-0888 [MEDIUM] CVE-1999-0888: dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
nvd
CVE-2003-0634P4HIGHCVSS 7.5venterprise_8.1.5_.0.0venterprise_8.1.5_.0.2+11 more2003-08-27
CVE-2003-0634 [HIGH] CVE-2003-0634: Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and
Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.
nvd
CVE-2001-0126P4HIGHCVSS 7.5v8.1.72001-03-12
CVE-2001-0126 [HIGH] CVE-2001-0126: Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by re
Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
nvd
CVE-2001-0326P4HIGHCVSS 7.5v8.1.7_r32001-05-03
CVE-2001-0326 [HIGH] CVE-2001-0326: Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the > FilePermission.
nvd
CVE-2006-0262P4CRITICALCVSS 10.0venterprise_8.1.7.4vstandard_8.1.7.42006-01-18
CVE-2006-0262 [CRITICAL] CVE-2006-0262: Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9
Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6venterprise_8.0.5_.0.0venterprise_8.0.6_.0.0+17 more2004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2006-0552P4HIGHCVSS 7.5venterprise_8.1.7.4vstandard_8.0.6+2 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5,
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2004-1366P4MEDIUMCVSS 4.6venterprise_8.0.5_.0.0venterprise_8.0.6_.0.0+17 more2004-08-04
CVE-2004-1366 [MEDIUM] CWE-255 CVE-2004-1366: Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-read
Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
nvd
CVE-2004-1369P4MEDIUMCVSS 5.0venterprise_8.0.5_.0.0venterprise_8.0.6_.0.0+17 more2004-08-04
CVE-2004-1369 [MEDIUM] CVE-2004-1369: The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash)
The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.
nvd
CVE-2002-0566P4MEDIUMCVSS 5.0v8.1.7v8.1.7_.12002-07-03
CVE-2002-0566 [MEDIUM] CVE-2002-0566: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a d
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
nvd
CVE-2002-0560P4MEDIUMCVSS 5.0v8.1.7v8.1.7.12002-07-03
CVE-2002-0560 [MEDIUM] CVE-2002-0560: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain se
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
nvd
CVE-2004-1367P4MEDIUMCVSS 4.4venterprise_8.0.5_.0.0venterprise_8.0.6_.0.0+17 more2004-08-04
CVE-2004-1367 [MEDIUM] CWE-200 CVE-2004-1367: Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!")
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed
nvd
CVE-2002-1118P4MEDIUMCVSS 5.0v8.1.5v8.1.5.0.0_enterprise+9 more2002-10-28
CVE-2002-1118 [MEDIUM] CVE-2002-1118: TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remot
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.
nvd