CVE-2009-1968 – Oracle 10g Secure Enterprise Search - 'search_p_groups' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2009-1968
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. La vulnerabilidad no especificada en el componente Secure Enterprise Search en Database de Oracle versión 10.1.8.3, permite a los atacantes remotos afectar a la integridad por medio de vectores desconocidos. NOTA: la información anterior fue obtenida de la CPU de julio de 2009. • https://www.exploit-db.com/exploits/33082 http://archives.neohapsis.com/archives/bugtraq/2009-07/0110.html http://dsecrg.com/pages/vul/show.php?id=125 http://osvdb.org/55892 http://secunia.com/advisories/35776 http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html http://www.securityfocus.com/bid/35681 http://www.securitytracker.com/id?1022560 http://www.vupen.com/english/advisories/2009/1900 https://exchange.xforce.ibmcloud.com/vulnerabilities/51754 •
CVE-2009-1970 – Oracle 9i/10g Database - TNS Command Remote Denial of Service
https://notcve.org/view.php?id=CVE-2009-1970
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991. Vulnerabilidad no especificada en el componente Listener en Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4 y 11.1.0.7 permite a atacantes remotos afectar la disponibilidad a través de vectores desconocidos, una vulnerabilidad diferente a CVE-2009-0991. • https://www.exploit-db.com/exploits/33083 http://osvdb.org/55891 http://secunia.com/advisories/35776 http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html http://www.securityfocus.com/bid/35683 http://www.securitytracker.com/id?1022560 http://www.vupen.com/english/advisories/2009/1900 https://exchange.xforce.ibmcloud.com/vulnerabilities/51756 •
CVE-2009-0985
https://notcve.org/view.php?id=CVE-2009-0985
Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users with the IMP_FULL_DATABASE role to affect confidentiality, integrity, and availability. Vulnerabilidad no especificada en el componente Core RDBMS de Oracle Database v10.1.0.5, v10.2.0.4 y v11.1.0.6; permite a usuarios autenticados en remotos con el rol IMP_FULL_DATABASE comprometer la confidencialidad, integridad y disponibilidad. • http://secunia.com/advisories/34693 http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html http://www.securityfocus.com/bid/34461 http://www.securitytracker.com/id?1022052 http://www.us-cert.gov/cas/techalerts/TA09-105A.html •
CVE-2009-0978 – Oracle DB SQL Injection Via SYS.LT.ROLLBACKWORKSPACE
https://notcve.org/view.php?id=CVE-2009-0978
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0975. Vulnerabilidad no especificada en el componente Workspace Manager en Oracle Database 10.2.0.4 y 11.1.0.6 permite a usuarios remotos autenticados afectar la confidencialidad y la integridad a través de vectores desconocidos, una vulnerabilidad diferente a CVE-2009-0975. • http://osvdb.org/53734 http://secunia.com/advisories/34693 http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html http://www.securityfocus.com/bid/34461 http://www.securitytracker.com/id?1022052 http://www.us-cert.gov/cas/techalerts/TA09-105A.html •
CVE-2009-0981 – Oracle APEX 3.2 - Unprivileged DB users can see APEX Password hashes
https://notcve.org/view.php?id=CVE-2009-0981
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue allows remote authenticated users to obtain APEX password hashes from the WWV_FLOW_USERS table via a SELECT statement. Vulnerabilidad no especificada en el componente Application Express en Oracle Database v11.1.0.7 permite a usuarios remotos autenticados afectar a la confidencialidad, en relación con APEX. Unprivileged database users can see password hashes in APEX version 3.0. • https://www.exploit-db.com/exploits/8456 http://osvdb.org/53738 http://secunia.com/advisories/34693 http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html http://www.red-database-security.com/advisory/apex_password_hashes.html http://www.securityfocus.com/archive/1/502724/100/0/threaded http://www.securityfocus.com/bid/34461 http://www.securitytracker.com/id?1022052 http://www.us-cert.gov/cas/techalerts/TA09-105A.html •