Oracle / Application Server Web Cache
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2005-1382 | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter. | MEDIUM | 5.0 | May 2, 2005 |
| CVE-2005-1381 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_… | MEDIUM | 6.8 | May 2, 2005 |
| CVE-2002-1641 | Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors. | HIGH | 10.0 | Mar 28, 2005 |
| CVE-2004-0385 | Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrar… | HIGH | 10.0 | Apr 16, 2004 |
| CVE-2002-0566 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header w… | MEDIUM | 5.0 | Jun 11, 2002 |
| CVE-2002-0565 | Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sens… | MEDIUM | 5.0 | Jun 11, 2002 |
| CVE-2002-0564 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modi… | HIGH | 7.5 | Jun 11, 2002 |
| CVE-2002-0563 | The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including… | MEDIUM | 5.0 | Jun 11, 2002 |
| CVE-2002-0562 | The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attac… | MEDIUM | 5.0 | Jun 11, 2002 |
| CVE-2002-0561 | The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows rem… | HIGH | 7.5 | Jun 11, 2002 |
| CVE-2002-0560 | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1)… | MEDIUM | 5.0 | Jun 11, 2002 |
| CVE-2002-0559 | Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary co… | HIGH | 7.5 | Jun 11, 2002 |
| CVE-2002-0103 | An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain pr… | MEDIUM | 4.6 | Mar 15, 2002 |
| CVE-2002-0102 | Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number… | MEDIUM | 5.0 | Mar 15, 2002 |
| CVE-2001-0836 | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | HIGH | 7.5 | Mar 9, 2002 |
Showing 1 to 15 of 15 CVEs