CVE-2013-3751 – Oracle Database Server SQL QName Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-3751
Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Vulnerabilidad no especificada en el componente XML Parser en Oracle Database Server v11.2.0.2 y v11.2.0.3 permite a usuarios remotos autenticados afectar la confidencialidad, integridad y disponibilidad mediante vectores desconocidos. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Database. Authentication is not required to exploit this vulnerability. The specific flaw exists in the LpxFSMDom function. This function is responsible for parsing SQL commands through XML. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00000.html http://osvdb.org/95264 http://seclists.org/fulldisclosure/2014/Dec/23 http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/archive/1/534161/100/0/threaded http://www.securitytracker.com/id/1028789 http://www.vmware.com/security/advisories/VMSA-2014-0012.html https://exchange.xforce.ibmcloud.com •
CVE-2013-3760
https://notcve.org/view.php?id=CVE-2013-3760
Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-3771. Vulnerabilidad sin especificar en el componente Oracle executable en Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, y 11.2.0.3 , permite a usuarios locales comprometer la disponibilidad, confidencialidad e integridad a través de vectores desconocidos. Vulnerabilidad distinta de CVE-2013-3771. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00000.html http://osvdb.org/95265 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/bid/61209 http://www.securitytracker.com/id/1028789 https://exchange.xforce.ibmcloud.com/vulnerabilities/85652 •
CVE-2013-3790
https://notcve.org/view.php?id=CVE-2013-3790
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Privileged Account. Vulnerabilidad no especificada en el componente Core RDBMS en Oracle Database Server v10.2.0.4, v10.2.0.5, v11.1.0.7, v11.2.0.2, y v11.2.0.3 permite a usuarios remotos autenticados afectar la integridad mediante vectores relacionados con Privileged Account. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00000.html http://osvdb.org/95268 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/bid/61219 http://www.securitytracker.com/id/1028789 https://exchange.xforce.ibmcloud.com/vulnerabilities/85655 •
CVE-2013-3774
https://notcve.org/view.php?id=CVE-2013-3774
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Vulnerabilidad no especificada en el componente Network Layer en Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, y 11.2.0.3 permite a atacantes remotos comprometer la confidencialidad, integridad y disponibilidad a través de vectores desconocidos. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00000.html http://osvdb.org/95263 http://seclists.org/fulldisclosure/2014/Dec/23 http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/archive/1/534161/100/0/threaded http://www.securityfocus.com/bid/61207 http://www.securitytracker.com/id/1028789 http://www.vmware.com/security/advisories/VMSA-2014-0012& •
CVE-2013-3789
https://notcve.org/view.php?id=CVE-2013-3789
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Vulnerabilidad no especificada en el componente Core RDBMS en Oracle Database Server v10.2.0.4, v10.2.0.5, v11.1.0.7, v11.2.0.2, y v11.2.0.3 permite a usuarios remotos autenticados afectar la confidencialidad, integridad y disponibilidad mediante vectores desconocidos. • http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00000.html http://osvdb.org/95267 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securitytracker.com/id/1028789 https://exchange.xforce.ibmcloud.com/vulnerabilities/85654 •