CVE-2001-0941 – Oracle 8/9i - DBSNMP Oracle Home Environment Variable Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0941
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. • https://www.exploit-db.com/exploits/21044 http://marc.info/?l=bugtraq&m=100716693806967&w=2 http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf http://www.securityfocus.com/bid/3138 https://exchange.xforce.ibmcloud.com/vulnerabilities/7643 •
CVE-2001-0942
https://notcve.org/view.php?id=CVE-2001-0942
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp. • http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf http://seclists.org/lists/bugtraq/2001/Dec/0000.html http://www.securityfocus.com/bid/3137 https://exchange.xforce.ibmcloud.com/vulnerabilities/7645 •
CVE-2001-0832
https://notcve.org/view.php?id=CVE-2001-0832
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability." • http://marc.info/?l=bugtraq&m=100386756715645&w=2 http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf •
CVE-2001-1041
https://notcve.org/view.php?id=CVE-2001-1041
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable. • http://marc.info/?l=bugtraq&m=100395579811880&w=2 http://marc.info/?l=bugtraq&m=99677282117387&w=2 http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf http://www.securityfocus.com/bid/3135 •
CVE-2001-0515
https://notcve.org/view.php?id=CVE-2001-0515
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. • http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf http://xforce.iss.net/alerts/advise82.php •