Page 4 of 67 results (0.006 seconds)

CVSS: 10.0EPSS: 2%CPEs: 4EXPL: 0

02 Nov 2005 — Unspecified vulnerability in the HTTP Server in Oracle Application Server 1.0 up to 9.0.2.3 has unknown impact and attack vectors, as identified by Oracle Vuln# AS04. • http://secunia.com/advisories/17250 •

CVSS: 10.0EPSS: 1%CPEs: 7EXPL: 0

02 Nov 2005 — Unspecified vulnerability in Web Cache in Oracle Application Server 1.0 up to 9.0.4.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS13. • http://secunia.com/advisories/17250 •

CVSS: 10.0EPSS: 1%CPEs: 8EXPL: 0

02 Nov 2005 — Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14. • http://secunia.com/advisories/17250 •

CVSS: 7.5EPSS: 0%CPEs: 13EXPL: 0

31 Dec 2004 — The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD. • http://otn.oracle.com/deploy/security/pdf/2004alert65.pdf •

CVSS: 9.8EPSS: 20%CPEs: 70EXPL: 2

30 Jul 2004 — The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0. • https://www.exploit-db.com/exploits/24335 •

CVSS: 9.1EPSS: 0%CPEs: 15EXPL: 0

30 Mar 2004 — The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password. • http://marc.info/?l=bugtraq&m=108067040722235&w=2 •

CVSS: 7.5EPSS: 4%CPEs: 5EXPL: 1

31 Dec 2002 — The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails. • http://www.kb.cert.org/vuls/id/717827 •

CVSS: 9.8EPSS: 5%CPEs: 5EXPL: 1

31 Dec 2002 — SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter. • http://www.kb.cert.org/vuls/id/717827 •

CVSS: 7.5EPSS: 1%CPEs: 5EXPL: 0

31 Dec 2002 — Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2. • http://www.kb.cert.org/vuls/id/717827 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

31 Dec 2002 — Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print. • http://www.nextgenss.com/papers/hpoas.pdf •