← Back

Oracle

oracle

10,653 CVEs • 1,055 products

Products (1,055)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Jrockit
jrockit
Http Server
http_server
Openjdk
openjdk
Mysql Cluster
mysql_cluster
Siebel Crm
siebel_crm
Agile Plm
agile_plm
Marketing
marketing
Database
database
Javafx
javafx
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Coherence
coherence
Oracle8i
oracle8i
Istore
istore
Vm Server
vm_server
Database 10g
database_10g

CVEs (10,653)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Internet Directory
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
1Oracle
1Application Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP reque...Show more
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.Show less
1Oracle
1Mysql
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
3Hp
OracleSgi
3Hp Ux
IrixSolaris
Apr 16, 2026
Jun 18, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
1Oracle
1Internet Directory
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
1Oracle
2Application Server
Oracle8i
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configu...Show more
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.Show less
1Oracle
1Oracle8i
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
1Oracle
1Database Server
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
1Oracle
1Mysql
Apr 16, 2026
Feb 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
1Oracle
1Mysql
Apr 16, 2026
Feb 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
1Oracle
1Mysql
Apr 16, 2026
Jan 23, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
1Oracle
1Mysql
Apr 16, 2026
Jan 19, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
1Oracle
1Oracle8i
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.
1Oracle
1Application Server
Apr 16, 2026
Dec 31, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
1Oracle
1Application Server
Apr 16, 2026
Dec 31, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Data...Show more
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.Show less
1Oracle
2Internet Directory
Oracle8i
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
1Oracle
1Oracle8i
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.
1Oracle
1Mysql
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
1Oracle
1Listener
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE...Show more
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.Show less
1Oracle
1Web Listener
Apr 16, 2026
Jul 5, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.