Page 6 of 73 results (0.056 seconds)

CVSS: 8.8EPSS: 9%CPEs: 7EXPL: 0

04 Feb 2006 — Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been ... • http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041464.html •

CVSS: 10.0EPSS: 1%CPEs: 4EXPL: 0

18 Jan 2006 — Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 3%CPEs: 5EXPL: 0

18 Jan 2006 — Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component. NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 11%CPEs: 6EXPL: 0

18 Jan 2006 — Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 2%CPEs: 5EXPL: 1

18 Jan 2006 — Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXS... • http://secunia.com/advisories/18493 •

CVSS: 9.8EPSS: 1%CPEs: 3EXPL: 0

18 Jan 2006 — Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19. • http://secunia.com/advisories/18493 •

CVSS: 9.8EPSS: 1%CPEs: 4EXPL: 0

18 Jan 2006 — Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 2%CPEs: 10EXPL: 0

18 Jan 2006 — Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 1%CPEs: 7EXPL: 0

18 Jan 2006 — Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01. • http://secunia.com/advisories/18493 •

CVSS: 10.0EPSS: 2%CPEs: 7EXPL: 0

18 Jan 2006 — Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01. • http://secunia.com/advisories/18493 •