← Back

Oracle

oracle

10,484 CVEs • 1,055 products

Products (1,055)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Jrockit
jrockit
Http Server
http_server
Openjdk
openjdk
Siebel Crm
siebel_crm
Marketing
marketing
Agile Plm
agile_plm
Database
database
Javafx
javafx
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Mysql Cluster
mysql_cluster
Oracle8i
oracle8i
Istore
istore
Vm Server
vm_server
Database 10g
database_10g

CVEs (10,484)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Application Server
Apr 23, 2026
Mar 22, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table...Show more
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.Show less
1Oracle
1Application Server Portal
Apr 23, 2026
Mar 19, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.
1Oracle
1Database Server
Apr 23, 2026
Mar 14, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.
2Mysql
Oracle
2Mysql
Mysql
Apr 23, 2026
Mar 12, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure...Show more
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.Show less
1Oracle
1Apex
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it...Show more
Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it is likely that this issue overlaps one of the identifiers in CVE-2006-5351.Show less
1Oracle
1Database Server
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arb...Show more
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such as (1) utl_file.put_line and (2) utl_file.get_line, a related issue to CVE-2005-0701. NOTE: this issue is disputed by third parties who state that this is due to an insecure configuration instead of an inherent vulnerabilityShow less
1Oracle
1Apex
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV param...Show more
SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven.Show less
1Oracle
1Database Server
Apr 23, 2026
Mar 2, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was origi...Show more
Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third party, but the dispute was retracted. NOTE: this issue was called an "integer overflow" in the original source, but this might be incorrect.Show less
2Oracle
Sun
2Solaris
Sunos
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, wh...Show more
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.Show less
1Oracle
1Weblogic Portal
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server whil...Show more
BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.Show less
1Oracle
1Weblogic Portal
Apr 23, 2026
Jan 23, 2007
N/A· v4
N/A· v3
4.4 MEDIUM· v2
BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.
1Oracle
2Enterpriseone
Peoplesoft Enterprise
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.
1Oracle
2Enterpriseone
Peoplesoft Enterprise
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.
1Oracle
2Enterpriseone
Peoplesoft Enterprise
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.
1Oracle
1Enterprise Manager
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
1.7 LOW· v2
Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06.
1Oracle
1Enterprise Manager
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console....Show more
Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console. NOTE: EM05 might be related to CVE-2007-0222.Show less
1Oracle
1Enterprise Manager
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02. NOTE: EM05 might be related to CVE-2007-0222.
1Oracle
1E Business Suite
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.
1Oracle
1E Business Suite
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Pay...Show more
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).Show less
1Oracle
1Application Server
Apr 23, 2026
Jan 17, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.