cbcvebase.

Oracle Oracle9I vulnerabilities

47 known vulnerabilities affecting oracle/oracle9i.

Total CVEs
47
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH18MEDIUM19LOW2

Vulnerabilities

Page 2 of 3
CVE-2002-0559P3HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0559 [HIGH] CVE-2002-0559: Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote att Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a
nvd
CVE-2004-1368P4HIGHCVSS 7.8vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1368 [HIGH] CVE-2004-1368: ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
nvd
CVE-2002-1264P4HIGHCVSS 7.5v9.0v9.0.1+5 more2002-11-12
CVE-2002-1264 [HIGH] CVE-2002-1264: Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote at Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.
nvd
CVE-2002-0568P4LOWCVSS 2.1v9.0v9.0.12002-07-03
CVE-2002-0568 [LOW] CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
nvd
CVE-2006-0272P4CRITICALCVSS 9.0vstandard_9.2.0.72006-01-18
CVE-2006-0272 [CRITICAL] CVE-2006-0272: Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0 Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29. NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as
nvd
CVE-2003-0634P4HIGHCVSS 7.5vclient_9.2.0.1vclient_9.2.0.2+14 more2003-08-27
CVE-2003-0634 [HIGH] CVE-2003-0634: Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.
nvd
CVE-2003-1193P4HIGHCVSS 7.5v9.0.2v9.0.2.0.0+4 more2003-11-03
CVE-2003-1193 [HIGH] CVE-2003-1193: Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hi Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.
nvd
CVE-2006-0262P4CRITICALCVSS 10.0venterprise_9.0.1.5venterprise_9.0.1.5_fips+1 more2006-01-18
CVE-2006-0262 [CRITICAL] CVE-2006-0262: Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9 Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.
nvd
CVE-2002-0571P4HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0571 [HIGH] CVE-2002-0571: Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2004-1339P4MEDIUMCVSS 6.5v9.0v9.0.1+11 more2004-12-23
CVE-2004-1339 [MEDIUM] CWE-89 CVE-2004-1339: SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS defau SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.
nvd
CVE-2006-0552P4HIGHCVSS 7.5venterprise_9.0.1.4venterprise_9.0.1.5+3 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2004-1366P4MEDIUMCVSS 4.6vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1366 [MEDIUM] CWE-255 CVE-2004-1366: Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-read Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
nvd
CVE-2002-0562P4MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0562 [MEDIUM] CVE-2002-0562: The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP store The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
nvd
CVE-2005-1495P4HIGHCVSS 7.5v9.0v9.0.1+8 more2005-05-11
CVE-2005-1495 [HIGH] CVE-2005-1495: Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT st Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
nvd
CVE-2004-1338P4MEDIUMCVSS 6.5v9.0v9.0.1+11 more2004-12-23
CVE-2004-1338 [MEDIUM] CWE-264 CVE-2004-1338: The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partia The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to ex
nvd
CVE-2002-0565P4MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0565 [MEDIUM] CVE-2002-0565: Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
nvd
CVE-2004-1369P4MEDIUMCVSS 5.0vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1369 [MEDIUM] CVE-2004-1369: The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.
nvd
CVE-2002-0566P4MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0566 [MEDIUM] CVE-2002-0566: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a d PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
nvd
CVE-2002-0560P4MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0560 [MEDIUM] CVE-2002-0560: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain se PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
nvd
Oracle Oracle9I vulnerabilities | cvebase