CVE-2015-2655 – Oracle Application Express Cross Site Scripting
https://notcve.org/view.php?id=CVE-2015-2655
Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.3.00.08 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Vulnerabilidad no especificada en el componente Application Express en Oracle Database Server en versiones anteriores a 4.2.3.00.08, permite a usuarios remotos autenticados afectar la confidencialidad e integridad a través de vectores desconocidos. The gReport Controls Sort Widget in Oracle Application Express is prone to permanent cross site scripting. The setting "display as" of the column attributes is ignored for the filter list. Versions prior to 4.2.3.00.08 are affected. • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html http://www.securityfocus.com/bid/75864 http://www.securitytracker.com/id/1032903 •
CVE-2015-2585
https://notcve.org/view.php?id=CVE-2015-2585
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0 allows remote authenticated users to affect availability via unknown vectors. Vulnerabilidad no especificada en el componente Application Express en Oracle Database Server anterior a la versión 5.0, permite a usuarios remotos autenticados afectar la disponibilidad a través de vectores desconocidos. • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html http://www.securitytracker.com/id/1032903 •
CVE-2015-2586
https://notcve.org/view.php?id=CVE-2015-2586
Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect availability via unknown vectors. Vulnerabilidad no especificada en el componente Application Express en Oracle Database Server anterior a la versión 4.2.1, permite a atacantes remotos afectar la disponibilidad a través de vectores desconocidos. • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html http://www.securitytracker.com/id/1032903 •
CVE-2014-6483
https://notcve.org/view.php?id=CVE-2014-6483
Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Vulnerabilidad no especificada en el componente Application Express en Oracle Database Server anterior a 4.2.6 permite a usuarios remotos autenticados afectar a la confidencialidad, integridad y disponibilidad a través de vectores desconocidos. • http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html http://www.securityfocus.com/bid/70480 •
CVE-2007-4517 – Oracle - xdb.xdb_pitrig_pkg.PITRIG_DROPMETADATA procedure
https://notcve.org/view.php?id=CVE-2007-4517
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument. Desbordamiento de búfer en el procedimiento XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA en Oracle 10g R2 permite a usuarios remotos autenticados ejecutar código de su elección mediante un argumento (1) OWNER o (2) NAME. • https://www.exploit-db.com/exploits/18093 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=622 http://secunia.com/advisories/27526 http://securityreason.com/securityalert/8524 http://www.securityfocus.com/archive/1/483434/100/0/threaded http://www.securityfocus.com/bid/26374 http://www.securitytracker.com/id?1018908 http://www.vupen.com/english/advisories/2007/3803 https://exchange.xforce.ibmcloud.com/vulnerabilities/38318 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •