
CVE-2006-1866
https://notcve.org/view.php?id=CVE-2006-1866
20 Apr 2006 — Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10... • http://secunia.com/advisories/19712 •

CVE-2006-1868
https://notcve.org/view.php?id=CVE-2006-1868
20 Apr 2006 — Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03. Desbordamiento de búfer en el componente Advanced Replication en Oracle Database Server 10.1.0.4 permite a usuarios de la base de datos ejecutar código de su elección a través del procedimiento VERIFY_LOG del paquete DBMS_SNAPSHOT_UTL, también conocido como Vuln# DB03. • http://secunia.com/advisories/19712 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2006-1870
https://notcve.org/view.php?id=CVE-2006-1870
20 Apr 2006 — Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors in the Export component, aka Vuln# DB05. NOTE: details are unavailable from Oracle, but as of 20060427, they have not publicly commented on whether DB05 is the same issue as CVE-2006-2081. Vulnerabilidad no especificada en Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, y 10.2.0.2 con impacto y vectores de ataque desconocidos en el componente Export (Exporta... • http://secunia.com/advisories/19712 •

CVE-2006-1871
https://notcve.org/view.php?id=CVE-2006-1871
20 Apr 2006 — SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06. Vulnerabilidad de inyección de Oracle Database Server 9.2.0.7 y 10.1.0.5 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante la función DELETE_FROM_TALBE en el paquete DBMS_LOGMNGR_SESSION (Log Miner), tcc Vuln# DB06. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045280.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2006-1873
https://notcve.org/view.php?id=CVE-2006-1873
20 Apr 2006 — Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB08. Vulnerabilidad no especificada en Oracle Database Server 9.2.0.7, 10.1.0.4, y 10.2.0.1 con impacto y vectores de ataque desconocidos en el componente Oracle Spatial, tcc Vuln# DB08. • http://secunia.com/advisories/19712 •

CVE-2006-1875
https://notcve.org/view.php?id=CVE-2006-1875
20 Apr 2006 — Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11. NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS. Vulnerabilidad no especificad en Oracle Database Server 9.0.1.5, 9.2.0.7, y 10.1.0.5 con impacto y vectores de ataque desconocidos en el componente Oracle Spatial, tcc Vuln# DB11. • http://secunia.com/advisories/19712 •

CVE-2006-1876
https://notcve.org/view.php?id=CVE-2006-1876
20 Apr 2006 — Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GEN_RID_RANGE_BY_AREA and (2) GEN_RID_RANGE functions in the MDSYS.SDO_PRIDX package. Vulnerabilidad no especificada en Oracle Database Server 9.2.0.7 and ... • http://secunia.com/advisories/19712 •

CVE-2006-1884
https://notcve.org/view.php?id=CVE-2006-1884
20 Apr 2006 — Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. • http://secunia.com/advisories/19712 •

CVE-2006-0552
https://notcve.org/view.php?id=CVE-2006-0552
04 Feb 2006 — Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. • http://secunia.com/advisories/18493 •

CVE-2006-0547
https://notcve.org/view.php?id=CVE-2006-0547
04 Feb 2006 — Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been ... • http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041464.html •