← Back

Oracle

oracle

10,484 CVEs • 1,055 products

Products (1,055)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Jrockit
jrockit
Http Server
http_server
Openjdk
openjdk
Siebel Crm
siebel_crm
Marketing
marketing
Agile Plm
agile_plm
Database
database
Javafx
javafx
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Mysql Cluster
mysql_cluster
Oracle8i
oracle8i
Istore
istore
Vm Server
vm_server
Database 10g
database_10g

CVEs (10,484)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
2Application Server
Jsp
Apr 16, 2026
Aug 22, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
1Oracle
1E Business Suite
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users...Show more
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.Show less
1Oracle
1Oracle9i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listene...Show more
Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.Show less
1Oracle
1Oracle8i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.
1Oracle
2Oracle8i
Oracle9i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected o...Show more
Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.Show less
1Oracle
2Database Server
Oracle8i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
1Oracle
1Oracle9i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connectin...Show more
Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port.Show less
1Oracle
1Oracle8i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FI...Show more
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.Show less
1Oracle
1Oracle8i
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header exten...Show more
Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.Show less
1Oracle
1Internet Directory
Apr 16, 2026
Jul 17, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Oracle
1Internet Directory
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated b...Show more
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.Show less
1Oracle
1Internet Directory
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Oracle
1Application Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP reque...Show more
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.Show less
1Oracle
1Mysql
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
3Hp
OracleSgi
3Hp Ux
IrixSolaris
Apr 16, 2026
Jun 18, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
1Oracle
1Internet Directory
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
1Oracle
2Application Server
Oracle8i
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configu...Show more
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.Show less
1Oracle
1Oracle8i
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
1Oracle
1Database Server
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
1Oracle
1Mysql
Apr 16, 2026
Feb 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.